External risk intelligence

MISP Two-Factor Authentication Code Reuse Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-103655

MISP (Malware Information Sharing Platform) is commonly deployed as a web-based service accessible via the internet or across network segments to facilitate threat intelligence sharing, making its authentication and login interface a typically public-facing or externally reachable service.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the two-factor authentication process in MISP, allowing a valid code to be used more than once within its validity period. If an attacker can intercept a legitimate code during login, they could potentially use it to gain unauthorized access to a user's account and sensitive threat intelligence data. The main concern is confirming relevance and exposure within your deployed instances.

  • Login codes can be reused within seconds.
  • Protects sensitive threat intelligence data access.
  • Confirm if MISP is deployed and used.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized access to a user's account by intercepting a valid one-time code during a two-factor authentication login. This code, which is typically valid for 30 seconds, could be replayed within its validity window to authenticate a second session. This could lead to the compromise of sensitive threat intelligence data and administrative functions.

  • Attacker observes or intercepts a valid TOTP code.
  • Replays the code within its validity window.
  • Unauthorized account access and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a valid one-time code for two-factor authentication could be reused within its time window, allowing an attacker who intercepts a legitimate code to gain unauthorized access to a user's account. This could potentially expose sensitive threat-intelligence data and administrative functions.

  • Account access.
  • Code intercepted during login.
  • Compromised threat-intelligence data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in MISP's two-factor authentication requires immediate attention from teams managing the MISP platform and its associated security controls. The first practical step is to identify all instances of MISP, confirm their external reachability and business criticality, and then assign ownership for remediation planning based on the identified risk.

  • Assign MISP platform ownership.
  • Verify TOTP exposure and reachability.
  • Plan and coordinate vendor updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MISP and what is it used for?

MISP, or Malware Information Sharing Platform, is an open-source software project used by organizations to collect, correlate, and share threat intelligence. It provides a centralized interface for analysts to manage indicators of compromise, such as malicious IP addresses or file hashes, helping security teams collaborate on identifying and defending against cyber threats.

What does CVE-2026-103655 mean by replay vulnerability?

This CVE describes a weakness classified as CWE-294, which refers to an authentication bypass by capture-replay. In MISP, the system fails to track whether a specific time-based one-time password (TOTP) has already been used. Because the platform considers the code valid for its entire time window, an attacker can reuse a single intercepted code to authenticate themselves as the legitimate user before that window expires.

How does an attacker trigger this vulnerability?

To exploit this, an attacker must successfully capture a valid TOTP code while a user is logging in, such as through network interception or shoulder surfing. Simply knowing a user's password is not enough; the attacker must act within the active TOTP time window, which is typically 30 seconds. If a code is not intercepted or if the attacker attempts to use it after the time window closes, the attack will not succeed.

Is my MISP instance at risk of this authentication issue?

Halo Surface Signal indicates that MISP is frequently deployed as a web-facing service to facilitate data sharing, which often makes its login interface reachable from external networks. If your instance is accessible via the internet or sits on an exposed network segment, it carries a higher risk because the barrier for an attacker to observe or intercept login traffic is significantly lower than for internal-only services.

What is the first step to address this CVE?

Start by identifying all instances of MISP running in your environment to determine which systems are affected by versions prior to v2.5.48. Once you have a complete inventory, verify whether your instances are reachable from the internet, as this increases the likelihood of exploitation. Finally, ensure that platform ownership is clearly assigned so your team can coordinate the necessary software updates to close the authentication gap.

References