Misp-project
Misp-project Misp: vulnerabilidades y CVE
Misp-project Misp tiene 147 vulnerabilidades publicadas, 47 de ellas en los últimos 12 meses. 29 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE147
Últimos 12 meses47
Críticas29
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-95754 | Media (6.9) | 0.54% | — | 22 sept 2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The… |
| CVE-2026-95661 | Media (5.1) | 0.44% | — | 22 sept 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript… |
| CVE-2026-86452 | Alta (8.7) | 0.54% | — | 7 sept 2026 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an… |
| CVE-2026-86451 | Media (5.3) | 0.27% | — | 7 sept 2026 | Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorized to view the object… |
| CVE-2026-86441 | Baja (2.3) | 0.28% | — | 7 sept 2026 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor… |
| CVE-2026-86440 | Media (5.1) | 0.24% | — | 7 sept 2026 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL… |
| CVE-2026-86419 | Alta (7) | 0.42% | — | 7 sept 2026 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the… |
| CVE-2026-86418 | Baja (2.3) | 0.27% | — | 7 sept 2026 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The… |
| CVE-2026-86417 | Media (5.3) | 0.27% | — | 7 sept 2026 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering… |
| CVE-2026-86408 | Alta (7.1) | 0.34% | — | 7 sept 2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied… |
| CVE-2026-86351 | Media (5.1) | 0.26% | — | 7 sept 2026 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin… |
| CVE-2026-86347 | Alta (7.1) | 0.43% | — | 7 sept 2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied… |
| CVE-2026-86342 | Media (5.3) | 0.34% | — | 7 sept 2026 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's… |
| CVE-2026-85533 | Alta (7.6) | 0.37% | — | 4 sept 2026 | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster… |
| CVE-2026-85239 | Alta (7.1) | 0.45% | — | 3 sept 2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The… |
| CVE-2026-85238 | Alta (7.6) | 0.34% | — | 3 sept 2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity… |
| CVE-2026-85237 | Alta (8.6) | 0.46% | — | 3 sept 2026 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force… |
| CVE-2026-85236 | Alta (8.8) | 0.25% | — | 3 sept 2026 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET… |
| CVE-2026-85230 | Media (5.3) | 0.29% | — | 3 sept 2026 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the… |
| CVE-2026-85227 | Media (6.1) | 0.25% | — | 3 sept 2026 | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder… |
| CVE-2026-85226 | Media (5.3) | 0.25% | — | 3 sept 2026 | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other… |
| CVE-2026-85221 | Alta (7.6) | 0.27% | — | 3 sept 2026 | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value… |
| CVE-2026-85216 | Crítica (9.5) | 0.87% | — | 3 sept 2026 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate… |
| CVE-2026-78380 | Alta (8.7) | 0.45% | — | 24 ago 2026 | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual… |
| CVE-2026-60124 | Media (5.3) | 0.37% | — | 8 jul 2026 | An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import… |
| CVE-2026-56447 | Crítica (9.3) | 0.61% | — | 22 jun 2026 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted… |
| CVE-2026-56446 | Alta (8.7) | 0.69% | — | 22 jun 2026 | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site… |
| CVE-2026-56425 | Crítica (9.3) | 0.46% | — | 22 jun 2026 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the… |
| CVE-2026-56424 | Alta (7.1) | 0.52% | — | 22 jun 2026 | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a… |
| CVE-2026-56423 | Crítica (9.4) | 0.47% | — | 22 jun 2026 | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of… |