PT-2026-85081 · Misp · Misp
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
An issue in the email-based one-time password (OTP) authentication flow allows an attacker to perform an unrestricted number of OTP verification attempts. The
email otp() endpoint lacks brute-force protection when validating submitted OTP values. An attacker who has passed the primary authentication stage can repeatedly submit candidate OTP values while the same OTP remains valid, increasing the likelihood of guessing the code and bypassing the second authentication factor to gain unauthorized account access. This is further complicated because the OTP is linked to the user instead of a specific login session, enabling multiple concurrent sessions to guess the same valid OTP.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp