PT-2026-85081 · Misp · Misp

·

CVE-2026-85237

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description An issue in the email-based one-time password (OTP) authentication flow allows an attacker to perform an unrestricted number of OTP verification attempts. The email otp() endpoint lacks brute-force protection when validating submitted OTP values. An attacker who has passed the primary authentication stage can repeatedly submit candidate OTP values while the same OTP remains valid, increasing the likelihood of guessing the code and bypassing the second authentication factor to gain unauthorized account access. This is further complicated because the OTP is linked to the user instead of a specific login session, enabling multiple concurrent sessions to guess the same valid OTP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85237

Affected Products

Misp