PT-2026-96094 · Misp · Misp
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
The
login() function in UsersController.php contains insufficient HTTP method validation. The system uses an allowlist that only checks for POST and PUT methods before applying security controls. An unauthenticated attacker can use other HTTP methods to bypass bruteforce protection, email one-time-password (OTP) verification, and login-failure logging. This allows for unlimited credential-guessing attempts without rate-limiting, bypasses two-factor authentication, and removes the audit trail for failed login attempts, potentially leading to unauthorized access.Recommendations
Update to version 2.5.47 or later.
Fix
RCE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp