CVE-2026-86342
- EPSS 0.27%
- Veröffentlicht 07.09.2026 09:02:55
- Zuletzt bearbeitet 09.09.2026 15:22:56
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event...
CVE-2026-85239
- EPSS 0.24%
- Veröffentlicht 03.09.2026 15:37:47
- Zuletzt bearbeitet 11.09.2026 14:18:55
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed sema...
CVE-2026-85238
- EPSS 0.23%
- Veröffentlicht 03.09.2026 15:30:42
- Zuletzt bearbeitet 11.09.2026 14:17:04
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without ...
CVE-2026-85237
- EPSS 0.3%
- Veröffentlicht 03.09.2026 15:22:59
- Zuletzt bearbeitet 11.09.2026 14:15:51
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating subm...
CVE-2026-85236
- EPSS 0.2%
- Veröffentlicht 03.09.2026 15:13:00
- Zuletzt bearbeitet 11.09.2026 14:14:30
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to ...
CVE-2026-85230
- EPSS 0.31%
- Veröffentlicht 03.09.2026 14:48:41
- Zuletzt bearbeitet 10.09.2026 19:37:59
A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an a...
CVE-2026-85227
- EPSS 0.27%
- Veröffentlicht 03.09.2026 14:42:02
- Zuletzt bearbeitet 10.09.2026 19:38:21
MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping befor...
CVE-2026-85226
- EPSS 0.23%
- Veröffentlicht 03.09.2026 14:35:17
- Zuletzt bearbeitet 10.09.2026 19:39:34
MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions assoc...
CVE-2026-85221
- EPSS 0.09%
- Veröffentlicht 03.09.2026 14:16:59
- Zuletzt bearbeitet 10.09.2026 19:40:05
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verif...
CVE-2026-85216
- EPSS 0.48%
- Veröffentlicht 03.09.2026 13:59:35
- Zuletzt bearbeitet 10.09.2026 19:42:07
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAu...