External risk intelligence

MISP Authentication Bypass Vulnerability in LdapAuth and LinOTPAuth Plugins.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90961

MISP (Malware Information Sharing Platform) is designed as a web-based application to facilitate threat intelligence sharing. It is commonly deployed as an internet-facing or inter-organizational web portal, and the vulnerability exists directly within its authentication plugins, which are exposed via the platform's standard login web interface.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in certain authentication plugins for MISP could allow unauthorized access without a password, potentially granting attackers the same privileges as legitimate users, including access to sensitive threat intelligence data.

  • Bypass authentication to gain user access.
  • Sensitive data access is a potential consequence.
  • Confirm plugin relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can impersonate any user on a MISP instance by exploiting a flaw in its authentication plugins. The attacker begins by identifying a valid user's email address. They then send a login request with this email but provide an empty or malformed password. If the MISP instance uses the vulnerable LdapAuth or LinOTPAuth plugins, the system will incorrectly authenticate the attacker as the target user, granting them the user's privileges.

  • Requires affected plugin enabled.
  • Sends login with valid email, invalid password.
  • Grants unauthorized user privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to bypass authentication when the LdapAuth or LinOTPAuth plugins are enabled and an attacker knows a valid user's email address. This could lead to unauthorized access to user accounts and potentially administrative privileges within the MISP instance.

  • User account access.
  • Unauthenticated login bypass.
  • Unauthorized access to threat intelligence.

Operational Fix

Recommended remediation, mitigation, and detection steps

MISP administrators and platform teams are responsible for securing authentication mechanisms. The first practical step is to identify all MISP instances using the affected plugins, determine their exposure, and locate the accountable owner for remediation.

  • Identify MISP instances with affected plugins.
  • Verify exposure and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MISP and why is it used?

MISP, or Malware Information Sharing Platform, is a web-based tool designed to help organizations collect, store, and share threat intelligence. It allows teams to collaborate on tracking cyber threats and security indicators. The platform includes various authentication plugins, such as LdapAuth and LinOTPAuth, which help integrate the software with existing user directory services or multi-factor authentication systems.

What is the vulnerability in CVE-2026-90961?

This vulnerability falls under Improper Input Validation (CWE-20) and Improper Authentication (CWE-287). The affected plugins fail to verify that login credentials are non-empty strings. Because this essential safety check is missing, the system may treat an empty or malformed password as a successful authentication request, allowing an attacker to bypass the password requirement entirely and gain access to a user's account.

How does an attacker trigger this bypass?

An attacker must know a valid email address associated with a registered user on the MISP instance. By submitting a login request for that specific user with an empty or malformed password, they can exploit the plugin's logic error. This flaw is not triggered if these specific authentication plugins are disabled, nor does it work if the attacker lacks a valid email address recognized by the directory or user store.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies MISP as a platform frequently deployed as an internet-facing portal for inter-organizational intelligence sharing. Because the authentication plugins are directly exposed through the standard web login interface, any instance reachable via the internet is considered a high-priority target for unauthorized access.

What should I do if I run MISP?

First, confirm whether your MISP instance has the LdapAuth or LinOTPAuth plugins enabled, as these are the only components affected. Once you have identified all instances using these plugins, evaluate their exposure level and verify who is responsible for managing them. Coordinate with your team to review the official project updates for a fix and prepare to apply patches as soon as they become available.

References