{"api_version":"1","generated_at":"2026-10-08T08:02:37+00:00","cve":"CVE-2026-107180","urls":{"html":"https://cve.report/CVE-2026-107180","api":"https://cve.report/api/cve/CVE-2026-107180.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107180","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107180"},"summary":{"title":"MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances","description":"On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup.\n\nThe initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag).\n\nImpact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy.\n\nAffected version: <2.5.48","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-10-07 13:17:22","updated_at":"2026-10-07 15:17:19"},"problem_types":["CWE-287","CWE-306","CWE-287 CWE-287 Improper Authentication","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.1","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/8deb0619e","name":"https://github.com/MISP/MISP/commit/8deb0619e","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/MISP/MISP/commit/6b527ba6e","name":"https://github.com/MISP/MISP/commit/6b527ba6e","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107180","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107180","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.48 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The TOTP enrolment enforcement in the user verification path was extended from covering only standard browser requests to covering all non-browser request types (AJAX, REST, .json, automation). Any request that cannot follow the browser redirect to the TOTP setup page is now refused with a 403 Forbidden response if the user has not enrolled in TOTP and the instance requires it. Identities authenticated via API key remain exempt, as they are not browser sessions subject to the redirect-based enrolment flow.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Tanguy Snoeck","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 4.8","lang":"en"},{"source":"CNA","value":"Claude Opus 5","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-107180","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-07T14:40:43.846815Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-07T14:40:54.178Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["app/Controller/AppController.php (login / user verification / TOTP enforcement)"],"product":"MISP","programFiles":["app/Controller/AppController.php"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Tanguy Snoeck"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup.</p><p>The initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag).</p><p>Impact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy.</p><p>Affected version: &lt;2.5.48</p>"}],"value":"On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup.\n\nThe initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag).\n\nImpact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy.\n\nAffected version: <2.5.48"}],"impacts":[{"capecId":"CAPEC-128","descriptions":[{"lang":"en","value":"CAPEC-128 Exploiting Incorrectly Configured Access Control"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-07T12:45:57Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-07T12:49:40.483Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/8deb0619e"},{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/6b527ba6e"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The TOTP enrolment enforcement in the user verification path was extended from covering only standard browser requests to covering all non-browser request types (AJAX, REST, .json, automation). Any request that cannot follow the browser redirect to the TOTP setup page is now refused with a 403 Forbidden response if the user has not enrolled in TOTP and the instance requires it. Identities authenticated via API key remain exempt, as they are not browser sessions subject to the redirect-based enrolment flow.</p>"}],"value":"The TOTP enrolment enforcement in the user verification path was extended from covering only standard browser requests to covering all non-browser request types (AJAX, REST, .json, automation). Any request that cannot follow the browser redirect to the TOTP setup page is now refused with a 403 Forbidden response if the user has not enrolled in TOTP and the instance requires it. Identities authenticated via API key remain exempt, as they are not browser sessions subject to the redirect-based enrolment flow."}],"title":"MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected MISP version range is not specified in the patch metadata; the vulnerability is assumed to affect all versions prior to the fix commits (8deb0619e and 6b527ba6e) that contain the otp_required enforcement logic without the non-browser request guard.","The CAPEC-128 mapping is approximate; the bypass is of an authentication requirement (forced TOTP enrolment) rather than a traditional authorization rule, but CAPEC-128 is the closest available pattern for exploiting an access control that is not uniformly applied across all request paths.","CVSS VC:H assumes that bypassing the mandatory 2FA requirement constitutes a high confidentiality impact on the vulnerability component, as the instance-level security policy (requiring all users to have 2FA) is nullified for the affected user. If the instance's threat model considers 2FA as a defense-in-depth layer rather than a primary control, VC could be rated Lower.","The patch evidence does not indicate whether the vulnerability is exploitable by an external unauthenticated attacker; the analysis assumes the attacker is an authenticated user (PR:L) who has not yet enrolled in TOTP.","The two commits are treated as a single vulnerability per the patch_set_assumption; the first commit is an incomplete fix and the second is the complete fix."],"capecRationale":[{"capecId":"CAPEC-128","rationale":"The access control policy requiring TOTP enrolment is incorrectly scoped to only standard browser requests. An attacker (or the legitimate user) exploits this misconfiguration by issuing requests in a non-browser format (AJAX, REST, .json) that the access control check does not cover. This is the closest CAPEC to the observed bypass of a security control due to incomplete scoping of the enforcement logic. The mapping is approximate because the bypass is of an authentication requirement rather than a traditional authorization rule, but CAPEC-128 best captures the pattern of exploiting an access control that is not uniformly applied."}],"commit":"6b527ba6e6a32aa574aa050eadf36207506dcea2","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Tanguy Snoeck of NCIA"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5"}],"cvssRationale":"AV:N - the bypass is achieved over the network via HTTP requests. AC:L - the attack is trivially simple: change the request type (add X-Requested-With header, append .json, use REST endpoint). AT:N - no special target conditions. PR:L - the attacker needs a valid authenticated session (low privilege: any user account). UI:N - no victim interaction beyond the attacker's own request. VC:H - the two-factor authentication requirement is completely bypassed, meaning the confidentiality protection provided by mandatory 2FA is nullified; the user retains full data access without the second factor. VI:N, VA:N - no integrity or availability impact on the MISP component. SC:N, SI:N, SA:N - no impact on subsequent components. The primary impact is the bypass of an authentication control (confidentiality of the 2FA gate).","fixSummary":"The TOTP enrolment enforcement in the user verification path was extended from covering only standard browser requests to covering all non-browser request types (AJAX, REST, .json, automation). Any request that cannot follow the browser redirect to the TOTP setup page is now refused with a 403 Forbidden response if the user has not enrolled in TOTP and the instance requires it. Identities authenticated via API key remain exempt, as they are not browser sessions subject to the redirect-based enrolment flow.","generatedAt":"2026-10-07T12:45:57.120635Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":5,"confidence":"medium","model":"qwen3.8:27b","score":7}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"38ec10c8e322eb94d2b27a1bcc10f796f3ee2c2b943034c0944cd811a03cbae3","patchSummary":"In app/Controller/AppController.php, the __verifyUser method was modified. Patch 1 added a conditional block after the $isUserRequest definition that checks: the request is not a standard user request, it is an AJAX request, the user has no TOTP configured, Security.otp_required is enabled, the role does not have perm_skip_otp, and the current action is not one of the allowed exceptions (terms, change_pw, logout, login, totp_new). If all conditions are met, a ForbiddenException is thrown. Patch 2 replaced the $this->request->is('ajax') condition with empty($user['logged_by_authkey']), broadening the guard to all non-browser request types while explicitly exempting API-key-authenticated sessions.","patchTruncated":false,"patches":[{"commit":"8deb0619e5ed6b12a1aa94967c68c977eb05398f","date":"Wed, 23 Sep 2026 09:53:42 +0200","patchSha256":"9e42ef967102a3d0699101588e40e27539be35259a88cb334c863f5297bd8210","source":"https://github.com/MISP/MISP/commit/8deb0619e.patch","sourceUrl":"https://github.com/MISP/MISP/commit/8deb0619e.patch","subject":"fix: [login] enforce TOTP enrolment on AJAX requests"},{"commit":"6b527ba6e6a32aa574aa050eadf36207506dcea2","date":"Mon, 28 Sep 2026 13:55:35 +0200","patchSha256":"f97d3076e297ea0bd06c87bc95614730333485eb470be8022b0e400a000f1cbf","source":"https://github.com/MISP/MISP/commit/6b527ba6e.patch","sourceUrl":"https://github.com/MISP/MISP/commit/6b527ba6e.patch","subject":"fix: [login] Refuse every unenrolled session request, not"}],"source":"patch set (2 sources)","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-07T12:45:57Z","version":"2.0.3"},"subject":"fix: [login] Refuse every unenrolled session request, not","weaknessRationale":[{"cweId":"CWE-287","rationale":"The TOTP (two-factor) authentication requirement is not properly enforced across all request types. The authentication gate (forced TOTP enrolment) is bypassed for non-browser requests, allowing a user to operate without completing the required second factor. This is a failure to properly enforce an authentication requirement."},{"cweId":"CWE-306","rationale":"The critical function of enforcing TOTP enrolment on otp_required instances is missing for AJAX, REST, .json, and automation request paths. The authentication check is present for browser requests but absent for all other request shapes, constituting a missing authentication control on a critical security function."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (8deb0619e5ed6b12a1aa94967c68c977eb05398f): fix: [login] enforce TOTP enrolment on AJAX requests","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/8deb0619e.patch"],"timestamp":"2026-09-23T07:53:42Z","type":"fix-developed"},{"description":"Corrective change authored (6b527ba6e6a32aa574aa050eadf36207506dcea2): fix: [login] Refuse every unenrolled session request, not","id":"evt-fix-developed-2","references":["https://github.com/MISP/MISP/commit/6b527ba6e.patch"],"timestamp":"2026-09-28T11:55:35Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20116"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-107180","datePublished":"2026-10-07T12:49:40.483Z","dateReserved":"2026-10-07T12:49:37.658Z","dateUpdated":"2026-10-07T14:40:54.178Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-07 13:17:22","lastModifiedDate":"2026-10-07 15:17:19","problem_types":["CWE-287","CWE-306","CWE-287 CWE-287 Improper Authentication","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","ssvcData":{"timestamp":"2026-10-07T12:45:57Z","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"Supplier","version":"2.0.3"}},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-07T14:40:43.846815Z","id":"CVE-2026-107180","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107180","Ordinal":"1","Title":"MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Typ","CVE":"CVE-2026-107180","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107180","Ordinal":"1","NoteData":"On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could bypass the forced setup by issuing any non-browser request type, including AJAX/XHR calls, REST API requests, .json format URLs, restSearch queries, or automation actions. Because these machine-readable request shapes cannot follow the redirect that the browser path uses to send the user to the TOTP enrolment page, the guard simply skipped the check and the user retained full access to the instance without completing the required second-factor setup.\n\nThe initial fix (commit 8deb0619e) added a guard specifically for AJAX requests. A follow-up fix (commit 6b527ba6e) broadened the guard to cover every non-browser request shape, while preserving the exemption for identities authenticated via API key (logged_by_authkey flag).\n\nImpact: an authenticated user on an otp_required instance can operate with full access indefinitely without enrolling in TOTP, nullifying the instance-level two-factor authentication policy.\n\nAffected version: <2.5.48","Type":"Description","Title":"MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Typ"}]}}}