« Volver al listado

Misp-project

Misp-project Misp: vulnerabilidades y CVE

Misp-project Misp tiene 147 vulnerabilidades publicadas, 47 de ellas en los últimos 12 meses. 29 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE147
Últimos 12 meses47
Críticas29
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-95754Media (6.9)0.54%—22 sept 2026
In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The…
CVE-2026-95661Media (5.1)0.44%—22 sept 2026
MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript…
CVE-2026-86452Alta (8.7)0.54%—7 sept 2026
Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an…
CVE-2026-86451Media (5.3)0.27%—7 sept 2026
Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object…
CVE-2026-86441Baja (2.3)0.28%—7 sept 2026
Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor…
CVE-2026-86440Media (5.1)0.24%—7 sept 2026
Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL…
CVE-2026-86419Alta (7)0.42%—7 sept 2026
Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the…
CVE-2026-86418Baja (2.3)0.27%—7 sept 2026
Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The…
CVE-2026-86417Media (5.3)0.27%—7 sept 2026
Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering…
CVE-2026-86408Alta (7.1)0.34%—7 sept 2026
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied…
CVE-2026-86351Media (5.1)0.26%—7 sept 2026
Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin…
CVE-2026-86347Alta (7.1)0.43%—7 sept 2026
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied…
CVE-2026-86342Media (5.3)0.34%—7 sept 2026
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's…
CVE-2026-85533Alta (7.6)0.37%—4 sept 2026
An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster…
CVE-2026-85239Alta (7.1)0.45%—3 sept 2026
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The…
CVE-2026-85238Alta (7.6)0.34%—3 sept 2026
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity…
CVE-2026-85237Alta (8.6)0.46%—3 sept 2026
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force…
CVE-2026-85236Alta (8.8)0.25%—3 sept 2026
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET…
CVE-2026-85230Media (5.3)0.29%—3 sept 2026
A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the…
CVE-2026-85227Media (6.1)0.25%—3 sept 2026
MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder…
CVE-2026-85226Media (5.3)0.25%—3 sept 2026
MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other…
CVE-2026-85221Alta (7.6)0.27%—3 sept 2026
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value…
CVE-2026-85216Crítica (9.5)0.87%—3 sept 2026
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate…
CVE-2026-78380Alta (8.7)0.45%—24 ago 2026
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual…
CVE-2026-60124Media (5.3)0.37%—8 jul 2026
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import…
CVE-2026-56447Crítica (9.3)0.61%—22 jun 2026
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted…
CVE-2026-56446Alta (8.7)0.69%—22 jun 2026
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site…
CVE-2026-56425Crítica (9.3)0.46%—22 jun 2026
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the…
CVE-2026-56424Alta (7.1)0.52%—22 jun 2026
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a…
CVE-2026-56423Crítica (9.4)0.47%—22 jun 2026
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of…

Otros productos de Misp-project