MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.

Project Subscriptions

Vendors Products
Microrealestate Subscribe
Microrealestate Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 26 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title MicroRealEstate Authentication Bypass via OTP Brute-Force

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Tue, 21 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force in MicroRealEstate

Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force in MicroRealEstate

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Mon, 13 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Sun, 12 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microrealestate
Microrealestate microrealestate
Vendors & Products Microrealestate
Microrealestate microrealestate

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute-Force in MicroRealEstate

Wed, 08 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force Vulnerability in MicroRealEstate

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via OTP Brute‑Force Vulnerability in MicroRealEstate

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-07-07T13:35:02.868Z

Reserved: 2026-06-26T00:40:34.057Z

Link: CVE-2026-57867

cve-icon Vulnrichment

Updated: 2026-07-07T13:34:59.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses