OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103655

CRITICAL · CVSS 9.3 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in MISP's two-factor authentication (TOTP) process allows an attacker to replay a valid one-time code multiple times within its validity window, enabling unauthorized access to user accounts. This critical flaw poses a significant risk to any organization using TOTP for authentication, particularly those handling sensitive threat intelligence data. Organizations running versions prior to 2.5.48 should prioritize immediate remediation to mitigate potential account compromises.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103655
Severity
CRITICAL
CVSS
9.3
EPSS
0.31%

Original NVD Description

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.