CVE-2026-107278
- EPSS 0.25%
- Veröffentlicht 07.10.2026 15:42:42
- Zuletzt bearbeitet 07.10.2026 21:17:15
MISP contains a validation flaw in its object synchronization logic. When a MISP Object is created without a description, it is stored correctly on the originating instance. However, when that object is replicated to another MISP instance via the syn...
CVE-2026-107276
- EPSS 0.21%
- Veröffentlicht 07.10.2026 15:36:49
- Zuletzt bearbeitet 07.10.2026 21:17:14
MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that th...
CVE-2026-107180
- EPSS 0.32%
- Veröffentlicht 07.10.2026 12:49:40
- Zuletzt bearbeitet 07.10.2026 15:17:19
On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenticated user who had not yet enrolled in TOTP could b...
CVE-2026-107175
- EPSS 0.21%
- Veröffentlicht 07.10.2026 12:38:44
- Zuletzt bearbeitet 07.10.2026 15:17:19
MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its distribution ...
CVE-2026-106513
- EPSS 0.64%
- Veröffentlicht 06.10.2026 19:18:13
- Zuletzt bearbeitet 07.10.2026 17:16:50
MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust ...
CVE-2026-104912
- EPSS 0.21%
- Veröffentlicht 02.10.2026 16:16:49
- Zuletzt bearbeitet 03.10.2026 16:16:35
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale d...
CVE-2026-104914
- EPSS 0.22%
- Veröffentlicht 02.10.2026 16:16:49
- Zuletzt bearbeitet 06.10.2026 19:17:40
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the ...
CVE-2026-104910
- EPSS 0.27%
- Veröffentlicht 02.10.2026 16:16:48
- Zuletzt bearbeitet 03.10.2026 16:16:34
MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validat...
CVE-2026-104908
- EPSS 0.29%
- Veröffentlicht 02.10.2026 15:56:13
- Zuletzt bearbeitet 02.10.2026 17:17:05
MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag for...
CVE-2026-104907
- EPSS 0.35%
- Veröffentlicht 02.10.2026 15:51:34
- Zuletzt bearbeitet 02.10.2026 17:17:04
MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was...