CVE-2026-94379: MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP)
The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection, email one-time-password (OTP) verification, and login-failure logging. Because the checks were not exhaustive, an unauthenticated attacker could issue login requests using other HTTP methods and bypass all three security controls simultaneously. Specifically:
- the bruteforce blocklisting check and attempt counter were skipped, allowing unlimited credential-guessing attempts without being rate-limited or blocked - the email OTP two-factor authentication step was skipped, defeating the second factor of authentication - login-failure events were neither logged nor counted, removing the audit trail and the mechanism that would normally trigger a blocklist entry.
The security impact is the effective disabling of brute-force protection and multi-factor authentication for any attacker who can craft an HTTP request with a non-POST/PUT method to the login endpoint, potentially leading to credential compromise and unauthorized access to the MISP instance.
Version affected: <2.5.47
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MISPto a version that resolves this vulnerability.Fixed in <2.5.47 - Configuration
In UsersController.php within the login() function, replace the allowlist-style checks (only allowing POST/PUT before bruteforce protection, email OTP verification, and login-failure logging) with a denylist approach so that every non-GET HTTP method triggers: (1) bruteforce protection, (2) email OTP verification, and (3) login-failure logging.
MISP UsersController.php login() HTTP method validation = denylist: require is NOT GET (trigger security-critical branches for every non-GET method)
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send crafted HTTP requests to the MISP login endpoint can exploit it. The attacker does not need to use POST or PUT; a different HTTP method can bypass the affected checks.
What security controls are bypassed?
Non-POST/PUT login requests bypass bruteforce blocklist checks and attempt counting, email OTP verification, and login-failure logging. This permits unrestricted credential guessing and can allow login with a compromised password without completing the email OTP step.
Are failed exploit attempts visible in the normal login audit trail?
No. Login failures through the bypassed code path are neither logged nor counted, so they do not create the events or counters that would normally lead to blocklisting.
How can defenders identify potentially affected activity?
Review requests to the login endpoint for HTTP methods other than POST and PUT. Because failed attempts on this path are not logged or counted by the affected login controls, absence of expected login-failure records does not rule out attempted exploitation.