CVE Vulnerabilities

CVE-2026-103655

Authentication Bypass by Capture-replay

Published: Oct 01, 2026 | Modified: Oct 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.

The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a users login could replay it to authenticate a second session as that user.

Preconditions:

  • The target user has TOTP-based two-factor authentication enabled.

  • The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).

  • The replay must occur within the TOTP validity period.

Security impact:

  • Unauthorized account access by replaying a captured one-time code.

  • Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.

Affected versions: <v2.5.48.

Weakness

A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Potential Mitigations

References