Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY143 SECURITY RECORDS

misp

misp

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at misp, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-94379 21 Sep 2026 MISP: unspecified < 2.5.47 The fix replaces the allowlist-style HTTP method checks (is POST or PUT) with a denylist approach (is NOT GET) in all three security-critical branches of the login() function. This ensures that every non-GET HTTP method—regardless of whether it is POST, PUT, PATCH, DELETE, HEAD, OPTIONS, or any other—triggers the bruteforce protection, email OTP verification, and login-failure logging code paths, closing the method-based bypass. Update reference ↗
CVE-2026-94374 21 Sep 2026 MISP: < 2.5.47 The fix adds an unset($report['id']) call in the EventReport processing loop within processModuleResultsData, immediately before the event_id assignment and save() call. This ensures that any client-supplied id field is stripped from the report data, forcing the ORM to perform an insert (new report) rather than an update (existing report), consistent with the existing behavior of the attribute and object loops in the same method. Update reference ↗
CVE-2026-94373 21 Sep 2026 MISP: < 2.5.47 The vulnerability is remediated by replacing the unsafe innerHTML property assignments with the safe textContent property when setting the display text of dynamically created <option> elements. textContent inserts the value as plain text without parsing HTML, thereby neutralizing any injected markup or script. Update reference ↗
CVE-2026-94372 21 Sep 2026 MISP: < 2.5.47 The fix applies CakePHP's h() HTML-encoding function to each sample tag name before it is interpolated into the HTML notice. This ensures that any angle brackets, quotes, or ampersands contained in user-supplied tag names are rendered as inert HTML entities, preventing script execution in the administrator's browser. Update reference ↗
CVE-2026-94277 21 Sep 2026 MISP: < 2.5.47 The fix applies CakePHP's h() HTML-encoding function to the $galaxyName variable before it is passed to sprintf() for HTML output, ensuring that any special characters (angle brackets, quotes, etc.) in the galaxy name are percent-encoded and rendered as inert text rather than executable markup. Update reference ↗
CVE-2026-93296 17 Sep 2026 misp: unspecified < 2.5.47 The fix applies HTML output encoding to the user-controlled label variable (lbl) before it is interpolated into the innerHTML string in both affected view templates. By wrapping the label with escapeHtml(), any HTML metacharacters in object names are neutralized, preventing injected markup from being interpreted as executable HTML or JavaScript in the viewer's browser. Update reference ↗
CVE-2026-93295 17 Sep 2026 misp: < 2.5.47 < 2.5.47 The fix introduces a validation layer in BackgroundJobsTool::enqueue() that rejects any job argument matching a reserved CakePHP console path switch (-app, --app, -working, --working, -root, --root, -webroot, --webroot), throwing an InvalidArgumentException before the job is queued. Additionally, the EventsController::contact() method now casts the person field to a boolean, preventing it from ever forming a switch/value pair with the adjacent message field. Together, these changes ensure that user-supplied data can never be interpreted as a console path directive by the worker process. Update reference ↗
CVE-2026-92003 15 Sep 2026 MISP: < 2.5.46 The fix applies the existing hourly per-key log throttle to the two previously unguarded authentication-failure log writes. The throttle key is now derived from the client's source IP address rather than from caller-supplied input, preventing an attacker from generating unbounded Redis throttle entries. A per-request memo (stored in Configure::read('CurrentRequestAuthFailKeys')) is added to _shouldLog() to prevent duplicate log entries when beforeFilter() executes a second time via CakeErrorController on an exception, ensuring one request produces at most one log entry per key regardless of the operator's log_each_individual_auth_fail setting. Update reference ↗
CVE-2026-92002 15 Sep 2026 MISP: < 2.5.46 The _shouldLog() method now explicitly checks whether the Redis connection is available before attempting to use it. If setupRedis() returns false, the method immediately returns true, causing every authentication-failure event to be logged. This converts the previous fail-closed behavior (silence on dependency failure) into a fail-open behavior for security logging (log everything when the throttle state is unavailable), ensuring that a Redis outage cannot be used to suppress the audit trail of failed authentication attempts. Update reference ↗
CVE-2026-91859 15 Sep 2026 MISP: < 2.5.46 The fix introduces a per-instance boolean guard ($deferredWriterRegistered) in the AccessLog model so that logRequest() returns early on the second beforeFilter pass, preventing the error controller from overwriting the original request's log entry. Additionally, a $this->create() call is added before $this->save() in saveOnShutdown() to ensure each save issues an INSERT rather than an UPDATE, providing defense-in-depth against accidental row mutation. Update reference ↗
CVE-2026-91857 15 Sep 2026 MISP: < 2.5.46 The vulnerability is remediated by restricting all four state-changing actions to accept only POST requests via the CakePHP allowMethod() guard. Additionally, the client-side JavaScript for purgeUnusedPictures is updated to issue a POST request with the page's CSRF token in the X-CSRF-Token header, and a beforeFilter() hook is added to EventReportsController to configure header-only CSRF token validation for that specific action, since it is invoked via hand-built AJAX rather than a rendered form. Update reference ↗
CVE-2026-91851 15 Sep 2026 MISP: < 2.5.46 The fix corrects the type mismatch in the permission flag comparison by replacing the integer literal 0 with the explicit string values '' and '0', which are the actual database values representing an unrestricted dashboard template. This ensures MySQL performs a proper string-to-string comparison, so only rows genuinely marked as unrestricted are returned, restoring the intended per-permission-level access control on dashboard templates. Update reference ↗
CVE-2026-91846 15 Sep 2026 MISP: < 2.5.46 The fix introduces a dedicated __assertCanUseElements() authorization guard that is invoked in the beforeSave callback of the add() CRUD path (covering both form and REST submission) and in addElementToCollection(). For each element UUID, the method resolves the element type (deducing it if the caller omitted the field, preventing bypass by omission) and performs an ACL-aware lookup: for Events it calls fetchSimpleEvent() scoped to the current user, and for GalaxyClusters it calls fetchGalaxyClusters() with the user context. If the object does not exist or the caller lacks access, a NotFoundException is raised and the save is aborted. This ensures that no collection element can reference an object the caller is not authorized to read. Update reference ↗
CVE-2026-91825 15 Sep 2026 MISP: < 2.5.46 The fix adds an explicit authorization check for the sharing_group_id in the code path where the distribution field is omitted from the edit request. In the controller, if no distribution is submitted but a sharing_group_id is present and differs from the stored value, the user's access to that sharing group is verified via checkIfCanBeUsed before the edit proceeds. In the model's _edit method, a parallel check via checkIfAuthorised is added for the same condition, returning an error if the user is not authorized for the submitted sharing group. This closes the gap where omitting the distribution field bypassed the existing authorization gate. Update reference ↗
CVE-2026-91819 15 Sep 2026 MISP: < 2.5.46 The fix introduces a __rejectUnsafeMethodOverride() check in BetterSecurityComponent::startup() that executes before the parent SecurityComponent::startup() computes $hasData. It inspects both the _method POST field and the X-HTTP-Method-Override header (mirroring CakePHP's precedence) and rejects any value that is not a string in the allowed set {POST, PUT, PATCH, DELETE}. Non-string values (e.g., array payloads like _method[]=GET) are also refused. A BadRequestException is thrown and the event is logged, preventing the request from ever reaching the parent security logic with an emptied body. Update reference ↗
CVE-2026-90961 14 Sep 2026 MISP: < 2.5.46 The fix adds explicit type and emptiness validation for the email and password fields in both LdapAuthenticate and LinOTPAuthenticate before any authentication logic is invoked. Non-string or empty credentials are rejected with a logged error and a false return. Additionally, the LDAP authenticator now assigns a cryptographically random password to auto-provisioned user accounts instead of an empty string, preventing the stored hash of '' from being verifiable in the mixed-authentication fallback path. The LinOTP authenticator also rejects an empty password specifically in the mixed-authentication branch where the password is checked against the local database. Update reference ↗
CVE-2026-90957 14 Sep 2026 MISP: < 2.5.46 A new sandboxInlineFile() method is added to RestResponseComponent. When a file is served inline (download=false) and its type is SVG (svg, svgz, or image/svg+xml), the response is augmented with a Content-Security-Policy header containing the sandbox directive (which assigns an opaque origin and disables script execution, plugins, and form submission) along with restrictive default-src, style-src, img-src, and font-src directives that still permit rendering of inline styles, embedded raster images, and data: fonts. An X-Content-Type-Options: nosniff header is also set. The method is invoked from both the generic sendFile() path and the org-logo endpoint. The enable_svg_logos setting description is updated to warn administrators that SVG files remain XML documents and should be left disabled unless required. Update reference ↗
CVE-2026-90955 14 Sep 2026 MISP: < 2.5.46 The fix introduces a process-wide static identity (setShellUser) on SysLogLogableBehavior that is resolved at write time rather than at setup time, so it survives lazy model loads that re-run setup() on the singleton. The behavior appends 'via CLI' to the log description for shell-originated rows, mirroring the request_type = CLI marker in the new audit engine. The CLI shell now publishes the impersonated user through both Configure::write('CurrentUserId') and SysLogLogableBehavior::setShellUser() before any write. Explicit extralog calls were added for CLI user edit, disable, and delete operations so the default audit engine records them the same way the web path does. Background jobs that publish no user continue to log as SYSTEM without a CLI marker. Update reference ↗
CVE-2026-90895 14 Sep 2026 MISP: < 2.5.46 The fix replaces the shell's hand-rolled authorization logic with the same model-level accessors used by the web interface (Event::fetchSimpleEvent, MispAttribute::fetchAttributes, MispObject::fetchObjects, SharingGroup::checkIfAuthorised, Organisation::canSee), ensuring read and write operations enforce identical ACL rules. Credential columns are excluded at the query level via a hiddenFields mechanism so they are never fetched from the database. The inline detail editor now delegates to the entity-specific edit handlers, which enforce per-record write authorization. All terminal output passes through a sanitiser that neutralises C0/C1 control characters, ANSI escape sequences, and Unicode bidirectional overrides. Pagination is clamped to a safe range (1-1000) to prevent unbounded result sets. Update reference ↗
CVE-2026-90893 14 Sep 2026 MISP: < 2.5.46 The fix removes the three affected actions from the Security component's unlockedActions list (which had disabled all CSRF checks) and instead registers them under a header-only CSRF token validation mechanism (_csrfTokenHeaderOnly). This requires the X-CSRF-Token header to be present and valid on each request while still permitting the AJAX-style calls that lack traditional form fields. Client-side JavaScript and view templates are updated to include the X-CSRF-Token header (sourced from window.csrfToken) in all AJAX and fetch calls to these endpoints, ensuring legitimate same-origin requests continue to function while cross-origin forged requests are rejected. Update reference ↗
CVE-2026-88921 10 Sep 2026 unspecified < 2.5.46 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-88915 10 Sep 2026 ≤ 2.5.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-86452 7 Sep 2026 MISP: ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86451 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86441 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86440 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86419 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86418 7 Sep 2026 MISP: ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86417 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86408 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86351 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86347 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86342 7 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-86283 6 Sep 2026 ≤ 2.5.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-85547 4 Sep 2026 ≤ 2.5.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-85546 4 Sep 2026 ≤ 2.4.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-85538 4 Sep 2026 ≤ 2.5.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-85533 4 Sep 2026 ≤ 2.5.45 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-85239 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85238 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85237 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85236 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85230 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85227 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85226 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85221 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-85216 3 Sep 2026 ≤ 2.5.45 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-67178 28 Jul 2026 < 2.5.41 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-61474 9 Jul 2026 ≤ 2.5.42 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-60125 8 Jul 2026 ≤ 2.5.42 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.