PT-2026-96094 · Misp · Misp

·

CVE-2026-94379

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description The login() function in UsersController.php contains insufficient HTTP method validation. The system uses an allowlist that only checks for POST and PUT methods before applying security controls. An unauthenticated attacker can use other HTTP methods to bypass bruteforce protection, email one-time-password (OTP) verification, and login-failure logging. This allows for unlimited credential-guessing attempts without rate-limiting, bypasses two-factor authentication, and removes the audit trail for failed login attempts, potentially leading to unauthorized access.
Recommendations Update to version 2.5.47 or later.

Fix

RCE

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94379

Affected Products

Misp