Junglewise Threat Intelligence

CVE-2026-85216: MISP authentication bypass in LDAP and LinOTP components

CVE-2026-85216 · Severity: critical · CVSS 9.8 · Published 2026-09-03

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is a threat-intelligence sharing platform used by organizations to collaborate on security incidents and malware analysis. An authentication bypass vulnerability in its LDAP and LinOTP authentication modules allows unauthenticated attackers to log in as legitimate users without knowing their passwords, potentially gaining access to sensitive intelligence data, modifying threat information, or compromising system configuration.

Technical details

The vulnerability stems from insufficient credential validation in custom MISP authentication components (LdapAuthenticate and LinOTPAuthenticate) that failed to replicate CakePHP's FormAuthenticate validation checks. Attackers can exploit this by submitting empty passwords, which may be accepted by LDAP servers configured to permit unauthenticated binds or by local password hash comparisons. Additionally, LDAP-provisioned accounts were created with empty local passwords instead of random ones, enabling fallback authentication. The vulnerability is network-accessible and requires only knowledge of a valid user email address; no authentication is needed. The patch enforces string-type validation for credentials, rejects empty passwords appropriately, and generates random passwords for LDAP-provisioned accounts.

Affected products

  • MISP Project MISP

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: advisory: CVE-2026-85216 published