← Back to the live CVE advisory feed

CVE-2026-90961: MISP

Severity
9.3 (CRITICAL)
Vendor
MISP
Affected versions
0 through before 2.5.46
Patch status
Unknown
Published
2026-09-14T14:17:21.270
Modified
2026-09-14T14:17:21.270

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() input validation guard. As a result, the email and password fields extracted from the login request are passed to downstream authentication logic without verifying that they are non-empty strings. In the LDAP authenticator, an empty or null password is forwarded to ldap_bind(). Per RFC 4513 section 5.1.2, a bind request with a valid DN and an empty password constitutes an unauthenticated bind, which many LDAP directory servers accept as successful. An attacker who knows any valid user email address in the directory can therefore authenticate as that user without possessing a password. Additionally, non-string values (null, false, arrays) are either coerced to empty strings by ldap_bind(), raise TypeErrors, or are misinterpreted as find conditions in _findUser(), all of which can lead to unintended authentication outcomes. In the LinOTP authenticator, the same missing guard allows non-string credentials to be concatenated into the LinOTP verification request, and in the mixed-authentication branch an empty password is accepted against a stored hash of the empty string. A secondary issue in the LDAP authenticator is that newly created user accounts (auto-provisioned on first LDAP login) were assigned an empty password. Because the save path skips validation, the empty string is hashed and stored. If the user later ceases to be found in LDAP and the mixed-authentication fallback is used, the stored hash of the empty string verifies against an empty password, again permitting unauthenticated access. The vulnerability requires that the affected plugin (LdapAuth or LinOTPAuth) is enabled on the MISP instance and that the attacker knows at least one valid email address registered in the directory or MISP user store. No prior authentication is required. Successful exploitation grants the attacker the full privileges of the impersonated user, which may include administrative access to threat intelligence data. Version affected: ≤2.5.45

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 14, 2026 04:00 PM UTC
334 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-81648
CryptoPayment Gateway
Reporter: CONTACT
10
CRITICAL
VIEW RECORD
CVE-2026-82434
Apache Storm Nimbus PATCH
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-90898
Bifrost
Reporter: REEFS
9.8
CRITICAL
VIEW RECORD
CVE-2026-57123
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57125
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-21391
PingAM
Reporter: RESPONSIBLE-DISCLOSURE
9.5
CRITICAL
VIEW RECORD
CVE-2026-90680
DIR-823G
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-85192
Conditional Content Pro extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-90692
DIR-878
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-90693
DIR-878
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-90937
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-90919
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-90961
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
9.3
CRITICAL
VIEW RECORD
CVE-2026-12258
REST API
Reporter: CVE-COORDINATION
9.2
CRITICAL
VIEW RECORD
CVE-2026-74933
GenieWords
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-85129
Hoo Companion
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-88793
YouTube Embed
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2023-46273
Product identification pending PATCH
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2023-50461
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-90938
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-82762
FXA5000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82766
SGA1000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82770
RP-WAH-SR1
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82772
ECE1000
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82774
M2M Gateway Integrated Type CPS-MG341*
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82777
Integrated Type CPS-PC341[][]-*-9201
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82779
CPS-TM341G5MB-ADSC1-931
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82780
CPS-TM341G5MB-ADSC1-931
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82787
CPSL-08P1EN
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82789
CONPROSYS HMI System(CHS)
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82791
CAN-2-WF
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-82794
SV-CPT-MC310
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-90689
W20E
Reporter: CNA
8.7
HIGH
VIEW RECORD
CVE-2026-89180
Product identification pending
Reporter: TWCERT
8.7
HIGH
VIEW RECORD
CVE-2026-90934
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90605
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90606
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90607
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-90608
A3002MU
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2023-45858
Product identification pending PATCH
Reporter: CVE
8.6
HIGH
VIEW RECORD
CVE-2026-82765
FXA5000
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-82768
SGA1000
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-82793
CAN-2-WF
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-90699
DWR-M920
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-78375
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-90932
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-15600
raty
Reporter: CVD
8.6
HIGH
VIEW RECORD
CVE-2026-7848
raty PATCH
Reporter: CVD
8.6
HIGH
VIEW RECORD
CVE-2026-12518
Product identification pending
Reporter: CVE-COORDINATION
8.5
HIGH
VIEW RECORD
CVE-2026-90702
DWR-M921
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-90703
DWR-M921
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-20773
Product identification pending
Reporter: RESPONSIBLE-DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-57126
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-68955
The installer for Rakuten Kobo Desktop Application (Windows version)
Reporter: VULTURES
8.4
HIGH
VIEW RECORD
CVE-2026-90895
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.4
HIGH
VIEW RECORD
CVE-2024-58383
Product identification pending PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-82786
Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*
Reporter: VULTURES
8.2
HIGH
VIEW RECORD
CVE-2026-37008
CrewAI
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-25687
Product identification pending
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-57130
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-59569
Product identification pending
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-23789
Exynos 850 firmware
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-90894
Parallels Desktop for Mac PATCH
Reporter: REEFS
7.8
HIGH
VIEW RECORD
CVE-2026-90948
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-90949
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-29811
Product identification pending PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-31278
BioStar 2 PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-90930
Product identification pending
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-88802
MDJM Event Management PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-15891
Product identification pending
Reporter: VULNERABILITIES
7.5
HIGH
VIEW RECORD
CVE-2026-33963
Exynos 1330 firmware
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2023-32803
ca-certificates
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-85189
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85190
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85191
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-85195
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88852
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88853
Product identification pending
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-57129
praisonaiagents PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-59570
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-36453
Product identification pending PATCH
Reporter: CVE
7.4
HIGH
VIEW RECORD
CVE-2026-73195
Product identification pending PATCH
Reporter: SECURITY
7.3
HIGH
VIEW RECORD
CVE-2023-28148
Product identification pending PATCH
Reporter: CVE
7.2
HIGH
VIEW RECORD
CVE-2026-90929
filebrowser
Reporter: DISCLOSURE
7.2
HIGH
VIEW RECORD
CVE-2026-90688
W20E
Reporter: CNA
7.1
HIGH
VIEW RECORD
CVE-2026-8821
Product identification pending
Reporter: RESPONSIBLEDISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90927
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90928
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90933
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90939
Product identification pending
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-71198
Product identification pending PATCH
Reporter: CVE
7
HIGH
VIEW RECORD
CVE-2026-81564
Product identification pending
Reporter: SECURITY
7
HIGH
VIEW RECORD
CVE-2026-90593
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90596
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90601
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90603
Product identification pending
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-82784
Product identification pending
Reporter: VULTURES
6.9
MEDIUM
VIEW RECORD
CVE-2026-85188
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD
CVE-2026-79700
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD
CVE-2026-81565
Product identification pending
Reporter: SECURITY
6.9
MEDIUM
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.