CVE-2026-56422
- EPSS 0.6%
- Veröffentlicht 22.06.2026 11:43:02
- Zuletzt bearbeitet 22.06.2026 18:16:49
Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and rela...
CVE-2026-54398
- EPSS 0.22%
- Veröffentlicht 12.06.2026 21:08:15
- Zuletzt bearbeitet 23.07.2026 09:10:00
An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or vi...
CVE-2026-54397
- EPSS 0.23%
- Veröffentlicht 12.06.2026 20:55:53
- Zuletzt bearbeitet 15.06.2026 20:46:57
A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distrib...
CVE-2026-54396
- EPSS 0.25%
- Veröffentlicht 12.06.2026 20:48:18
- Zuletzt bearbeitet 15.06.2026 20:46:57
An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitt...
CVE-2026-54395
- EPSS 0.26%
- Veröffentlicht 12.06.2026 20:36:09
- Zuletzt bearbeitet 15.06.2026 20:46:57
MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HTML-decode ...
CVE-2026-54394
- EPSS 0.32%
- Veröffentlicht 12.06.2026 20:30:25
- Zuletzt bearbeitet 15.06.2026 20:46:57
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remai...
CVE-2026-54393
- EPSS 0.38%
- Veröffentlicht 12.06.2026 20:21:48
- Zuletzt bearbeitet 15.06.2026 20:46:57
A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, inc...
CVE-2026-54362
- EPSS 0.21%
- Veröffentlicht 12.06.2026 20:08:55
- Zuletzt bearbeitet 15.06.2026 20:46:57
An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organisation. The custom access-control condition intended to restrict galaxie...
CVE-2026-54361
- EPSS 0.26%
- Veröffentlicht 12.06.2026 19:59:58
- Zuletzt bearbeitet 15.06.2026 20:46:57
MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, i...
CVE-2026-54360
- EPSS 0.23%
- Veröffentlicht 12.06.2026 19:51:44
- Zuletzt bearbeitet 15.06.2026 20:46:57
A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the s...