Junglewise Threat Intelligence

CVE-2026-90961: MISP LdapAuth and LinOTPAuth authentication bypass

CVE-2026-90961 · Severity: info · CVSS 8.8 · Published 2026-09-14

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP's LDAP and LinOTP authentication plugins contain a flaw that allows attackers to log in as any known user without a password. The plugins fail to validate that password fields are non-empty before processing login attempts. An attacker who knows a valid email address in the directory can gain full access to threat intelligence data and administrative functions without authentication.

Technical details

The LdapAuth and LinOTPAuth authentication plugins fail to replicate CakePHP's FormAuthenticate._checkFields() input validation, allowing non-empty string checks to be bypassed. In LDAP, empty or null passwords are passed to ldap_bind(), which per RFC 4513 accepts unauthenticated binds with a valid DN and empty password as successful. In LinOTP, non-string credentials can be concatenated into verification requests, and empty passwords match stored hashes of empty strings in mixed-authentication mode. A secondary issue affects auto-provisioned LDAP users who are assigned empty passwords that are hashed and stored, enabling authentication bypass via the fallback mechanism. No prior authentication is required; the attacker must only know a valid email address in the directory or user store. Successful exploitation grants full user privileges including potential administrative access.

Affected products

  • MISP Project MISP ≤2.5.45

Timeline

  • 2026-09-14: disclosed: CVE-2026-90961 published