CVE-2026-107180
Last modified
CVE-2026-107180 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions.
Description
On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup. The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag). Impact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy. Affected version: <2.5.48
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107180?
How severe is CVE-2026-107180?
How do I fix CVE-2026-107180?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10717Out of bounds write and reads in openSeaChest’s --showSCSIDe…1.8
- CVE-2026-107170A flaw was found in m17n-lib. A partial failure during libra…2.9
- CVE-2026-107174A flaw was found in source-to-image. When unpacking archive …6.4
- CVE-2026-107175MISP contains a defect in its event save workflow that preve…5.3
- CVE-2026-107177Express Gateway through 1.16.11 contains a hardcoded cryptog…5.9
- CVE-2026-10718Out of bounds write in openSeaChest’s Trim/Unmap operation i…4.6
- CVE-2026-107181Telegram Desktop before 7.2.9 contains an IPC record-separat…8.1
- CVE-2026-107183llama.cpp before b11393 contains a use-after-free and double…8.1
- CVE-2026-10719Out of bounds write in openSeaChest’s --showSupportedFormats…1.8
- CVE-2026-107194Sungrow iSolarCloud before 2026 allows authentication bypass…9.2
- CVE-2026-1072The Keybase.io Verification plugin for WordPress is vulnerab…4.3
- CVE-2026-10720Canonical MicroCeph versions from the squid and tentacle tra…5.1
Are you affected by CVE-2026-107180?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
