CVE-2026-86452
- EPSS 0.34%
- Veröffentlicht 07.09.2026 13:03:27
- Zuletzt bearbeitet 14.09.2026 07:17:23
Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value wit...
CVE-2026-86451
- EPSS 0.24%
- Veröffentlicht 07.09.2026 12:59:43
- Zuletzt bearbeitet 09.09.2026 15:23:58
Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object the reference belongs to. Th...
CVE-2026-86441
- EPSS 0.22%
- Veröffentlicht 07.09.2026 12:39:20
- Zuletzt bearbeitet 09.09.2026 15:24:22
Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authent...
CVE-2026-86440
- EPSS 0.26%
- Veröffentlicht 07.09.2026 12:35:10
- Zuletzt bearbeitet 09.09.2026 15:24:29
Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or ...
CVE-2026-86419
- EPSS 0.33%
- Veröffentlicht 07.09.2026 12:31:35
- Zuletzt bearbeitet 09.09.2026 15:25:49
Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destinati...
CVE-2026-86418
- EPSS 0.21%
- Veröffentlicht 07.09.2026 12:22:52
- Zuletzt bearbeitet 14.09.2026 07:17:23
Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fi...
CVE-2026-86417
- EPSS 0.21%
- Veröffentlicht 07.09.2026 12:17:43
- Zuletzt bearbeitet 09.09.2026 15:26:08
Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same auth...
CVE-2026-86408
- EPSS 0.21%
- Veröffentlicht 07.09.2026 12:11:18
- Zuletzt bearbeitet 09.09.2026 15:26:17
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive ...
CVE-2026-86351
- EPSS 0.33%
- Veröffentlicht 07.09.2026 09:59:34
- Zuletzt bearbeitet 09.09.2026 15:26:26
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an exter...
CVE-2026-86347
- EPSS 0.29%
- Veröffentlicht 07.09.2026 09:30:58
- Zuletzt bearbeitet 09.09.2026 15:26:35
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-manage...