Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY138 SECURITY RECORDS

misp

misp

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at misp, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-104914 2 Oct 2026 MISP: < 2.5.48 The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user's organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic. Update reference ↗
CVE-2026-104912 2 Oct 2026 MISP: < 2.5.48 The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage. Update reference ↗
CVE-2026-104910 2 Oct 2026 MISP: < 2.5.48 The fix enforces proper per-event authorization on the related events query by applying the user's full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list. Update reference ↗
CVE-2026-104908 2 Oct 2026 MISP: < 2.5.48 The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes. Update reference ↗
CVE-2026-104907 2 Oct 2026 MISP: < 2.5.48 The vulnerability is remediated by casting the remote tag ID to an integer before embedding it in the inline JavaScript onclick handler. This ensures only a numeric value is rendered, eliminating the possibility of breaking out of the JavaScript string context with special characters. Update reference ↗
CVE-2026-104906 2 Oct 2026 MISP: < 2.5.48 The fix applies HTML-encoding (via the h() helper) to the JSON string before it is interpolated into the HTML pre element. This ensures that any HTML or script markup present in the JSON string properties of a TAXII object is rendered as inert text rather than being parsed and executed by the browser, eliminating the XSS vector. Update reference ↗
CVE-2026-104901 2 Oct 2026 MISP: < 2.5.48 The vulnerability is remediated by enforcing integer typing on the remote event ID at the point where it enters the application data structure in the controller, and by applying HTML output encoding (the h() helper) to all user-visible fields (remote_id, server_id) in both the default and Overmind-themed ID Translator views. This ensures that even if a remote server returns non-numeric or markup-laden data, it cannot be interpreted as HTML by the browser. Update reference ↗
CVE-2026-104900 2 Oct 2026 MISP: < 2.5.48 The vulnerability is remediated by applying HTML entity encoding to the count field value before it is rendered in the view template. This ensures that any HTML or script markup contained in the value from a remote server is neutralized and displayed as inert text rather than being interpreted by the browser. Update reference ↗
CVE-2026-103858 1 Oct 2026 MISP: unspecified < 2.5.48 The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association. Update reference ↗
CVE-2026-103664 1 Oct 2026 MISP: < 2.5.48 The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector. Update reference ↗
CVE-2026-103662 1 Oct 2026 MISP: < 2.5.48 The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector. Update reference ↗
CVE-2026-103659 1 Oct 2026 MISP: < 2.5.48 The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner. Update reference ↗
CVE-2026-103655 1 Oct 2026 MISP: < 2.5.48 The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window. Update reference ↗
CVE-2026-103651 1 Oct 2026 MISP: < 2.5.48 The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused. Update reference ↗
CVE-2026-103389 30 Sep 2026 MISP: < 2.5.48 The vulnerability is remediated by enforcing strict input validation on the galaxy icon field so that only valid Font Awesome icon names (lowercase alphanumeric characters and dashes) are accepted at write time. The sync/import capture path discards any icon value that does not conform. The correlation graph JSON generation falls back to a safe default icon for any previously stored invalid value. On the client side, both correlation graph scripts now set the icon as a CSS class attribute rather than injecting it as raw HTML, and apply an additional regex sanitization pass. The asset cache-busting version is incremented to ensure browsers load the corrected scripts. Update reference ↗
CVE-2026-103388 30 Sep 2026 MISP: < 2.5.48 The fix restricts the rendering of the Galaxy Cluster source field as a hyperlink to only http:// and https:// URLs by adding a regular-expression check (preg_match for ^https?://) in addition to the existing FILTER_VALIDATE_URL validation. This prevents javascript: and other non-HTTP URI schemes from being rendered as clickable links, eliminating the stored XSS vector. The change is applied consistently in both the default theme and the Overmind theme. Update reference ↗
CVE-2026-103321 30 Sep 2026 MISP: < 2.5.48 The vulnerability is remediated by enforcing strict server-side validation of the preview image field, restricting it to a well-formed base64-encoded PNG data URL, and by replacing the client-side string-concatenation rendering with DOM-based attribute assignment that does not interpret the value as HTML. Update reference ↗
CVE-2026-103239 30 Sep 2026 MISP: < 2.5.48 The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path. Update reference ↗
CVE-2026-103237 30 Sep 2026 MISP: < 2.5.48 The fix introduces a defensive save() override in the base model class that refuses to persist any record where the data array simultaneously contains a nested key matching the model alias and other top-level scalar fields, logging a warning and returning false. Additionally, all code paths that sanitize and save records (free-text import, module result processing, object delta merge, attribute bulk edit, sighting capture, shadow attribute proposal, event report creation) now explicitly unset the nested alias key from the data array before calling save(), ensuring the ORM cannot be redirected to an attacker-chosen row. Controller-level request reshaping was also corrected to avoid creating self-referencing data structures. Update reference ↗
CVE-2026-103235 30 Sep 2026 MISP: < 2.5.48 The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records. Update reference ↗
CVE-2026-95806 22 Sep 2026 MISP: < 2.5.47 The phar stream wrapper is unregistered via stream_wrapper_unregister('phar') at the top of both the web and console entry points, before any framework bootstrap or application code executes. Because no MISP component, CakePHP, or runtime library requires the phar wrapper, removing it eliminates the implicit unserialize() sink and the directory-like phar archive behavior without functional impact. This closes the deserialization and code-execution primitive application-wide, independent of whether individual callers validate their path arguments. Update reference ↗
CVE-2026-95805 22 Sep 2026 MISP: < 2.5.47 The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string 'theming_enabled*' to the correct 'theming_enabled', restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry. Update reference ↗
CVE-2026-95754 22 Sep 2026 MISP: < 2.5.47 The fix adds User.disabled to the fields array of the pre-authentication find() query so that the disabled-user check in the TOTP branch reads the actual column value and correctly rejects disabled users before they reach the TOTP verification step, restoring the intended guard behavior. Update reference ↗
CVE-2026-95703 22 Sep 2026 MISP: < 2.5.47 The is_uploaded_file() guard is hoisted to execute immediately after the basic size/error check and before any filesystem probe (file_exists, MIME detection, EXIF reading). If the tmp_name is empty or does not correspond to a genuine PHP upload, the method returns false early, preventing any filesystem interaction with an attacker-controlled path and eliminating the information oracle. Update reference ↗
CVE-2026-95701 22 Sep 2026 MISP: < 2.5.47 The fix corrects the logo directory path from the obsolete app/webroot/img/orgs to the current files/img/orgs location, expands the lookup to cover id, name, and uuid fields across png and svg extensions (mirroring the getOrgLogo helper), and adds a security guard: the candidate path is resolved with realpath() and verified via str_starts_with() against the resolved base directory, so any organization name containing traversal sequences (../) that would resolve outside files/img/orgs is rejected. Update reference ↗
CVE-2026-95698 22 Sep 2026 MISP: < 2.5.47 The fix adds input validation in findOrgImage so that each organization identifier value (id, name, uuid) is checked to be a non-empty plain filename component. Values containing path separators (detected via basename comparison) or dot-dot sequences are rejected, preventing the constructed path from escaping the designated org-image directory. The validated value is then used in the file_exists call and the returned image reference. Update reference ↗
CVE-2026-95697 22 Sep 2026 MISP: < 2.5.47 The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap. Update reference ↗
CVE-2026-95693 22 Sep 2026 MISP: < 2.5.47 The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration. Update reference ↗
CVE-2026-95685 22 Sep 2026 MISP: < 2.5.47 The ACL mapping for the replaceSuggestionInReport action was corrected from the wildcard permission ('*') to the perm_add permission, aligning it with all other report-modification actions and ensuring that only users explicitly granted the add permission can invoke the action. Update reference ↗
CVE-2026-95683 22 Sep 2026 MISP: < 2.5.47 The report fetch in the Overmind event enrichment now applies the caller's ACL via EventReport::buildACLConditions($user), enforcing the report's own distribution policy in addition to the event-level access. A condition on EventReport.deleted = 0 is also added to exclude soft-deleted reports. The query is further hardened with recursive = -1 and an explicit contain clause to limit the data retrieved. Update reference ↗
CVE-2026-95682 22 Sep 2026 MISP: unspecified < 2.5.47 The fix replaces the raw PHP echo of the organization name with a json_encode() call using the flags JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT. This produces a properly escaped JavaScript string literal that neutralizes quotes, angle brackets, ampersands, and other metacharacters, preventing breakout from the string context and subsequent script injection. Update reference ↗
CVE-2026-95679 22 Sep 2026 MISP: < 2.5.47 The fix introduces a custom XML input type handler in AppController::beforeFilter() that validates the request body contains an XML document marker (the < character) before passing it to the XML decoder. If the body does not contain <, it returns an empty array, preventing the Xml::build() locator/fetch code path from being reached regardless of the vendored library's internal guard logic. This ensures only actual XML documents are processed, eliminating the SSRF vector. Update reference ↗
CVE-2026-95674 22 Sep 2026 MISP: < 2.5.47 The fix adds a moduleFound flag that is set only when the requested module name matches an entry in the enabled modules list. After the lookup loop completes, if the flag remains false, the method throws a MethodNotAllowedException with the message 'Module not found or not available,' effectively rejecting any query that references a module not present in the enabled set. Update reference ↗
CVE-2026-95671 22 Sep 2026 MISP: < 2.5.47 The authorization guard in CollectionsController::add() was extended to cover PUT requests in addition to POST requests. The sharing-group usability check (which validates that the current user can use the target sharing group) and the element capture logic now execute regardless of whether the request arrives as POST or PUT, ensuring that CRUDComponent::add() cannot persist a collection with an unauthorized sharing group via either HTTP verb. Update reference ↗
CVE-2026-95667 22 Sep 2026 MISP: < 2.5.47 The installer scripts now explicitly create the log file with 0600 permissions using install -m 0600 and the FIFO with mkfifo -m 0600, ensuring both are root-readable/writable only from the moment of creation. The log file is also removed (rm -f) before creation to prevent a pre-existing symlink in /var/log from being used to redirect the write to an attacker-controlled path. This matches the existing 0600 treatment applied to /root/misp_settings.txt by the save_settings() function. Update reference ↗
CVE-2026-95665 22 Sep 2026 MISP: < 2.5.47 The vulnerability is remediated by adding the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags to the json_encode() call at the rendering sink. These flags cause angle brackets, single quotes, double quotes, and ampersands to be hex-encoded (e.g., ' becomes \u0027), preventing any of these characters from breaking out of the single-quoted JavaScript string literal and thereby eliminating the script injection vector. Update reference ↗
CVE-2026-95661 22 Sep 2026 MISP: < 2.5.47 The fix replaces the unsafe raw PHP loop that concatenated type values into a JavaScript array literal with a call to json_encode() using the JSON_HEX_TAG, JSON_HEX_APOS, JSON_HEX_QUOT, and JSON_HEX_AMP flags. This ensures that all special characters (angle brackets, quotes, ampersands) in the type values are hex-encoded, preventing any value from breaking out of the JavaScript string/array context and injecting arbitrary script. Update reference ↗
CVE-2026-95659 22 Sep 2026 MISP: < 2.5.47 The fix introduces two layers of defense. First, the viewForObject action now validates the object_type parameter against the AnalystData::valid_targets whitelist and rejects any value not in that list with a NotFoundException, preventing arbitrary strings from reaching the view layer. Second, the two output sinks in the Overmind thread.ctp template now apply the h() HTML-encoding function to the object type before interpolation into translated strings, ensuring that even if a valid type were to contain special characters, it would be rendered as inert text rather than executable markup. Update reference ↗
CVE-2026-95658 22 Sep 2026 MISP: < 2.5.47 The moduleStatelessExecution action is removed from the unlockedActions list, restoring the CSRF token check. A new mechanism (_csrfTokenHeaderOnly) is introduced that enforces the CSRF token while exempting only the field hash, which the legitimate caller (the module dialog) cannot produce because it posts a hand-built object. The module dialog's AJAX request is updated to send the CSRF token in the X-CSRF-Token header, satisfying the token check without requiring a field hash. Update reference ↗
CVE-2026-94404 21 Sep 2026 MISP: < 2.5.47 The editField action is removed from the Security component's unlockedActions list and added to the _csrfTokenHeaderOnly array. This enforces CSRF token validation (accepted either in the X-CSRF-Token header or in the request body) while dropping only the field-hash check, which the existing AJAX callers (Overmind index and legacy inline forms) cannot satisfy. Legitimate callers are unaffected because they already transmit a valid CSRF token. Update reference ↗
CVE-2026-94401 21 Sep 2026 MISP: < 2.5.47 The fix introduces two defensive measures in addMISPExportFile(): (1) a pre-parse validation that rejects any uploaded content not containing an XML document marker (the '<' character), preventing path or URL strings from reaching the XML parser; and (2) an explicit readFile => false option passed to Xml::build(), which disables the library's ability to interpret the input as a file path or URL to be read or fetched. Together these changes ensure that only genuine XML document content is parsed and that no server-side file access or network request is triggered by user-supplied data. Update reference ↗
CVE-2026-94394 21 Sep 2026 MISP: < 2.5.47 The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation. Update reference ↗
CVE-2026-94393 21 Sep 2026 MISP: < 2.5.47 The fix adds an ownership check in editReport: before adopting an existing report found by UUID, the code now verifies that the report's event_id matches the event being edited. If the UUID resolves to a report belonging to a different event, the operation is rejected with an error message, preventing cross-event reparenting, unauthorized read, and unauthorized overwrite of reports. Update reference ↗
CVE-2026-94383 21 Sep 2026 MISP: < 2.5.47 The vulnerability is remediated by enforcing a strict whitelist of allowed file extensions (txt, list, blocklist, csv) on the blocklist filename parameter before the file is processed. Any filename with an extension outside this whitelist is rejected with an error, preventing an attacker from placing files with executable or dangerous extensions (e.g., .php, .phtml) into the MISP export directory where they could be interpreted by the web server. Update reference ↗
CVE-2026-94381 21 Sep 2026 MISP: < 2.5.47 The fix removes the call to User::getAuthUser() and Auth::login() from the updateLoginTime() method, which was re-authenticating the user with their full role permissions. It replaces this with a call to _refreshAuth(), which refreshes the authentication state while preserving the current (restricted) permission level associated with the API key, preventing privilege escalation. Update reference ↗
CVE-2026-94379 21 Sep 2026 MISP: unspecified < 2.5.47 The fix replaces the allowlist-style HTTP method checks (is POST or PUT) with a denylist approach (is NOT GET) in all three security-critical branches of the login() function. This ensures that every non-GET HTTP method—regardless of whether it is POST, PUT, PATCH, DELETE, HEAD, OPTIONS, or any other—triggers the bruteforce protection, email OTP verification, and login-failure logging code paths, closing the method-based bypass. Update reference ↗
CVE-2026-94374 21 Sep 2026 MISP: < 2.5.47 The fix adds an unset($report['id']) call in the EventReport processing loop within processModuleResultsData, immediately before the event_id assignment and save() call. This ensures that any client-supplied id field is stripped from the report data, forcing the ORM to perform an insert (new report) rather than an update (existing report), consistent with the existing behavior of the attribute and object loops in the same method. Update reference ↗
CVE-2026-94373 21 Sep 2026 MISP: < 2.5.47 The vulnerability is remediated by replacing the unsafe innerHTML property assignments with the safe textContent property when setting the display text of dynamically created <option> elements. textContent inserts the value as plain text without parsing HTML, thereby neutralizing any injected markup or script. Update reference ↗
CVE-2026-94372 21 Sep 2026 MISP: < 2.5.47 The fix applies CakePHP's h() HTML-encoding function to each sample tag name before it is interpolated into the HTML notice. This ensures that any angle brackets, quotes, or ampersands contained in user-supplied tag names are rendered as inert HTML entities, preventing script execution in the administrator's browser. Update reference ↗
CVE-2026-94277 21 Sep 2026 MISP: < 2.5.47 The fix applies CakePHP's h() HTML-encoding function to the $galaxyName variable before it is passed to sprintf() for HTML output, ensuring that any special characters (angle brackets, quotes, etc.) in the galaxy name are percent-encoded and rendered as inert text rather than executable markup. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.