Executive brief
MISP is a threat-intelligence sharing platform used by organizations to collaborate on security incidents and malware analysis. An authentication bypass vulnerability in its LDAP and LinOTP authentication modules allows unauthenticated attackers to log in as legitimate users without knowing their passwords, potentially gaining access to sensitive intelligence data, modifying threat information, or compromising system configuration.
Technical details
The vulnerability stems from insufficient credential validation in custom MISP authentication components (LdapAuthenticate and LinOTPAuthenticate) that failed to replicate CakePHP's FormAuthenticate validation checks. Attackers can exploit this by submitting empty passwords, which may be accepted by LDAP servers configured to permit unauthenticated binds or by local password hash comparisons. Additionally, LDAP-provisioned accounts were created with empty local passwords instead of random ones, enabling fallback authentication. The vulnerability is network-accessible and requires only knowledge of a valid user email address; no authentication is needed. The patch enforces string-type validation for credentials, rejects empty passwords appropriately, and generates random passwords for LDAP-provisioned accounts.
Affected products
- MISP Project MISP
Timeline
- 2026-09-03: disclosed
- 2026-09-03: advisory: CVE-2026-85216 published