CVE-2026-92002
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true when a Redis instance existed and no throttle key was present. Therefore, when Redis was unavailable, the function did not allow the log write at all, effectively silencing authentication-failure logging for the duration of the outage. Version affected: ≤2.5.45
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-778
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- MISP MISP
Weakness type
Related vulnerabilities
- CVE-2024-48967 — Life2000 ventilator and Service PC lack sufficient audit logging capabilities
- CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-32967 — OpenEMR doesn't log password administration properly
- CVE-2023-1995 — Insufficient Logging Vulnerability in HiRDB