VYPR
Vypr IntelligenceAI-generatedOct 7, 2026· 5 CVEs

MISP Platform Hit by Five Vulnerabilities, Including High-Severity Auth Bypass

A batch of five vulnerabilities, including a High severity flaw in TOTP enforcement, were disclosed for the MISP threat intelligence platform between October 6-7, 2026.

Key findings

  • Five vulnerabilities in MISP disclosed between October 6-7, 2026, impacting various core functions.
  • High severity flaw (CVE-2026-107180) allows bypass of mandatory TOTP enrollment via non-browser requests.
  • Medium severity issues include object sync flaws (CVE-2026-107278), OTP race conditions (CVE-2026-107276), and event correlation defects (CVE-2026-107175).
  • Critical infrastructure settings like Redis hosts were exposed via UI and API (CVE-2026-106513).
  • Users are urged to update MISP to patched versions to address these security concerns.

On October 7, 2026, a batch of five vulnerabilities affecting the MISP threat intelligence platform was disclosed, spanning disclosures from October 6th to 7th. These vulnerabilities, with severities ranging from Medium to High, highlight issues in object synchronization, authentication flows, two-factor authentication enforcement, event correlation, and the exposure of critical infrastructure settings. The timely disclosure of these flaws underscores the importance of prompt patching for organizations utilizing MISP to protect their threat intelligence data and infrastructure.

One of the disclosed vulnerabilities, CVE-2026-107278, is a Medium severity flaw in MISP's object synchronization logic. The issue arises when a MISP Object is created without a description on the originating instance. While it is stored correctly locally, the receiving instance's validation rules reject the object during replication via the sync mechanism, potentially leading to incomplete or inconsistent data across distributed MISP instances.

CVE-2026-107276, also rated Medium, points to a race condition within MISP's email-based one-time password (OTP) login process. The vulnerability occurs when two concurrent HTTP requests, both containing the same valid OTP, are submitted. This allows both requests to successfully authenticate and establish separate sessions, as the OTP value is read from the shared store, validated, and then deleted only after both requests have been processed.

A High severity vulnerability, CVE-2026-107180, affects MISP instances configured to enforce Two-Step Verification (TOTP) enrollment. The enforcement mechanism was found to be bypassed by authenticated users who had not yet enrolled in TOTP. Such users could circumvent the mandatory setup by issuing non-browser requests, including API calls, thereby posing a significant security risk by allowing unauthorized access or actions before TOTP enrollment.

Furthermore, CVE-2026-107175, a Medium severity issue, impacts MISP's event save workflow. This defect prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook does not properly trigger the necessary recalculation, potentially leading to inaccurate or outdated correlation data.

Finally, CVE-2026-106513, a Medium severity vulnerability, involves the exposure of critical infrastructure settings through MISP's web UI and API. Site-admin users could view sensitive information such as Redis host addresses used by the core application, ZeroMQ plugin, and SimpleBackgroundJobs plugin. Compounding this, background job workers trust raw Redis job payloads without sufficient validation, creating a risk for attackers who gain access to these exposed settings.

The MISP team has addressed these vulnerabilities. Users are strongly advised to update their MISP instances to the latest patched versions to mitigate these risks. Maintaining up-to-date security configurations and regularly reviewing access controls are crucial steps in safeguarding MISP deployments against such vulnerabilities. The coordinated disclosure of these five CVEs highlights the ongoing need for vigilance in securing complex security intelligence platforms.

AI-written article. Grounded in 5 CVE records listed below.