CVE-2026-92003: MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion

Published Sep 15, 2026
·
Updated

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle.

Two API authentication failure branches wrote directly to the Log model:

- API requests with no authentication key;  - requests supplying an API key with an incorrect length

Unlike other authentication failures, these paths bypassed shouldLog(), so every request could create another durable authfail entry.

Version affected: ≤2.5.45

Affected Software

1 affected component
Misp Misp<=2.5.45

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in ≤2.5.45

Event History

Sep 15, 2026
CVE Published
via MITRE·11:43 AM
Data Sourced
via MITRE·11:43 AM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which requests can trigger the excessive log writes?

The affected paths are API requests with no authentication key and API requests that provide an API key of an incorrect length. Each such request can create a durable auth_fail log entry because these branches bypass the authentication-failure logging throttle.

2

Are deployments affected by this issue without a valid API key?

Yes. Requests with no authentication key are one of the affected API authentication-failure branches, so an attacker does not need a valid API key to trigger log writes through that path.

3

What versions are affected?

MISP versions 2.5.45 and earlier are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203