CVE-2026-94379
- EPSS 0.33%
- Veröffentlicht 21.09.2026 12:35:26
- Zuletzt bearbeitet 21.09.2026 16:17:30
The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enf...
CVE-2026-94374
- EPSS 0.24%
- Veröffentlicht 21.09.2026 12:25:02
- Zuletzt bearbeitet 21.09.2026 16:17:30
MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Un...
CVE-2026-94373
- EPSS 0.37%
- Veröffentlicht 21.09.2026 12:16:47
- Zuletzt bearbeitet 21.09.2026 16:17:30
MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Because innerHT...
CVE-2026-94372
- EPSS 0.23%
- Veröffentlicht 21.09.2026 12:02:17
- Zuletzt bearbeitet 21.09.2026 16:17:29
MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an informational...
CVE-2026-94277
- EPSS 0.26%
- Veröffentlicht 21.09.2026 09:25:04
- Zuletzt bearbeitet 21.09.2026 12:17:28
MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission can create or...
CVE-2026-93296
- EPSS 0.33%
- Veröffentlicht 17.09.2026 16:29:19
- Zuletzt bearbeitet 22.09.2026 08:16:42
MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category ...
CVE-2026-93295
- EPSS 0.5%
- Veröffentlicht 17.09.2026 16:25:40
- Zuletzt bearbeitet 22.09.2026 08:16:41
MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths(...
CVE-2026-92003
- EPSS 0.44%
- Veröffentlicht 15.09.2026 11:43:19
- Zuletzt bearbeitet 16.09.2026 13:42:48
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an...
CVE-2026-92002
- EPSS 0.39%
- Veröffentlicht 15.09.2026 11:24:21
- Zuletzt bearbeitet 16.09.2026 13:42:49
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns false when Redis ...
CVE-2026-91859
- EPSS 0.3%
- Veröffentlicht 15.09.2026 09:26:35
- Zuletzt bearbeitet 16.09.2026 13:42:48
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __acces...