CVE-2026-56447
- EPSS 0.3%
- Veröffentlicht 22.06.2026 12:39:31
- Zuletzt bearbeitet 23.06.2026 14:16:17
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration ...
CVE-2026-56446
- EPSS 0.31%
- Veröffentlicht 22.06.2026 12:31:40
- Zuletzt bearbeitet 23.06.2026 16:17:05
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could ...
CVE-2026-56425
- EPSS 0.3%
- Veröffentlicht 22.06.2026 12:25:00
- Zuletzt bearbeitet 26.06.2026 20:33:09
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the P...
CVE-2026-56424
- EPSS 0.31%
- Veröffentlicht 22.06.2026 12:17:17
- Zuletzt bearbeitet 23.06.2026 15:16:39
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated u...
CVE-2026-56423
- EPSS 0.23%
- Veröffentlicht 22.06.2026 11:56:26
- Zuletzt bearbeitet 23.06.2026 15:16:39
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for eac...
CVE-2026-10864
- EPSS 0.18%
- Veröffentlicht 04.06.2026 13:54:34
- Zuletzt bearbeitet 22.06.2026 19:23:18
A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became emp...
CVE-2026-10863
- EPSS 0.23%
- Veröffentlicht 04.06.2026 13:44:49
- Zuletzt bearbeitet 22.06.2026 19:23:18
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-co...
CVE-2026-10860
- EPSS 0.2%
- Veröffentlicht 04.06.2026 13:34:27
- Zuletzt bearbeitet 22.06.2026 19:23:18
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === nu...
CVE-2026-10861
- EPSS 0.22%
- Veröffentlicht 04.06.2026 13:26:05
- Zuletzt bearbeitet 22.06.2026 19:23:18
An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local a...
CVE-2026-10856
- EPSS 0.15%
- Veröffentlicht 04.06.2026 13:17:47
- Zuletzt bearbeitet 22.06.2026 19:23:18
A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, ...