CVE-2026-94379EPSS p45.7%
CVE-2026-94379CVE-2026-94379
Description
The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection, email one-time-password (OTP) verification, and login-failure logging. Because the checks were not exhaustive, an unauthenticated attacker could issue login requests using other HTTP methods and bypass all three security controls simultaneously. Specifically:
- the bruteforce blocklisting check and attempt counter were skipped, allowing unlimited credential-guessing attempts without being rate-limited or blocked
- the email OTP two-factor authentication step was skipped, defeating the second factor of authentication
- login-failure events were neither logged nor counted, removing the audit trail and the mechanism that would normally trigger a blocklist entry.
The security impact is the effective disab
Scoring
| EPSS | 0.58% probability of exploitation · percentile 45.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-21 |