Executive brief
MicroRealEstate is an open-source platform used by landlords to manage rental properties and tenants. A security flaw in the login process allows unauthorized individuals to bypass authentication by guessing one-time passwords (OTPs). If exploited, an attacker could gain full access to any user account, potentially exposing sensitive tenant information, financial records, and property management data.
Technical details
An authentication bypass vulnerability exists in MicroRealEstate due to improper token state management during the login process. The application fails to implement adequate rate limiting or state invalidation for One-Time Passwords (OTP), allowing a remote, unauthenticated attacker to perform a brute-force attack against the OTP. Successful exploitation allows the attacker to hijack any user session and gain unauthorized access to the management system. The vulnerability is present in versions up to and including 1.0.0-alpha3; no fixed version has been identified in the advisory.
Affected products
- Camel Aissani MicroRealEstate through 1.0.0-alpha3
Timeline
- 2026-07-07: disclosed: Initial disclosure date
- 2026-07-07: advisory: NVD and researcher advisory published