CVE-2026-103388
- EPSS 0.24%
- Veröffentlicht 30.09.2026 14:22:36
- Zuletzt bearbeitet 30.09.2026 16:17:08
MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on ...
CVE-2026-103321
- EPSS 0.36%
- Veröffentlicht 30.09.2026 12:19:01
- Zuletzt bearbeitet 30.09.2026 13:17:18
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HT...
CVE-2026-103239
- EPSS 0.26%
- Veröffentlicht 30.09.2026 10:16:18
- Zuletzt bearbeitet 30.09.2026 17:16:42
MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the int...
CVE-2026-103237
- EPSS 0.39%
- Veröffentlicht 30.09.2026 09:56:35
- Zuletzt bearbeitet 30.09.2026 18:18:15
MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, o...
CVE-2026-103235
- EPSS 0.36%
- Veröffentlicht 30.09.2026 09:09:36
- Zuletzt bearbeitet 30.09.2026 15:22:26
MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the ent...
CVE-2026-95806
- EPSS 0.39%
- Veröffentlicht 22.09.2026 15:09:09
- Zuletzt bearbeitet 22.09.2026 16:18:24
MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: - any filesystem opera...
CVE-2026-95805
- EPSS 0.41%
- Veröffentlicht 22.09.2026 14:59:22
- Zuletzt bearbeitet 22.09.2026 16:18:24
A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the M...
CVE-2026-95754
- EPSS 0.54%
- Veröffentlicht 22.09.2026 14:53:56
- Zuletzt bearbeitet 22.09.2026 16:18:24
In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.passwor...
CVE-2026-95703
- EPSS 0.51%
- Veröffentlicht 22.09.2026 14:49:42
- Zuletzt bearbeitet 22.09.2026 16:18:23
In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via...
CVE-2026-95701
- EPSS 0.76%
- Veröffentlicht 22.09.2026 14:44:21
- Zuletzt bearbeitet 22.09.2026 16:18:23
In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path construc...