CVE-2026-90961 | MISP up to 2.5.45 LdapAuth/LinOTPAuth _checkFields email/password hard-coded password (0ee058548 / EUVD-2026-77473)

SecurityVulns

A vulnerability labeled as critical has been found in MISP up to 2.5.45. Affected by this vulnerability is the function _checkFields of the component LdapAuth/LinOTPAuth. Executing a manipulation of the argument email/password can lead to use of hard-coded password.

This vulnerability is handled as CVE-2026-90961. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More