CVE-2026-103651
Last modified
CVE-2026-103651 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token.
Description
MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state. Preconditions: - The target user has HOTP (paper token) second-factor authentication enabled. - The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending). - The attacker has access to at least one HOTP token value (e.g., a paper token list). Security impact: - Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account. - Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays. Affected versions: <2.5.48.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103651?
How severe is CVE-2026-103651?
How do I fix CVE-2026-103651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103589QloApps through 1.7.0 contains a reflected cross-site script…5.4
- CVE-2026-103590QloApps through 1.7.0 contains a reflected cross-site script…5.4
- CVE-2026-103591DeepWiki-Open through commit d92819a contains an unauthentic…7.5
- CVE-2026-103592simple-php-router through 5.4.1.7 contains an IP restriction…6.5
- CVE-2026-1036The Photo Gallery by 10Web – Mobile-Friendly Image Gallery p…5.3
- CVE-2026-103641A flaw was found in GEGL. The Radiance HDR loader reads past…5.5
- CVE-2026-103655MISP contains a vulnerability in its two-factor authenticati…9.3
- CVE-2026-103656Rejected reason: this is rejected
- CVE-2026-103659MISP contains an authorization bypass in the event flattenin…7.1
- CVE-2026-103662MISP contains a reflected cross-site scripting (XSS) vulnera…5.1
- CVE-2026-103664MISP contains a reflected cross-site scripting (XSS) vulnera…4.8
- CVE-2026-103678A flaw was found in tnef. An attacker can exploit this vulne…5.4
Are you affected by CVE-2026-103651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
