Vulnerabilities in MISP

145 results
Vexday analysis

O MISP apresenta 13 vulnerabilidades catalogadas, sendo 5 divulgadas nos últimos 90 dias, o que indica atividade contínua de descoberta de falhas. Embora nenhuma esteja sob ataque ativo no momento, 2 vulnerabilidades críticas e a predominância de injeção de conteúdo (CWE-79) requerem atenção, especialmente considerando o papel estratégico da plataforma em ecossistemas de compartilhamento de inteligência de ameaças.

CVE-2026-86283HIGHMISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event DataEPSS 0.4%CVE-2026-94381HIGHMISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTimeEPSS 0.4%CVE-2026-54398MEDIUMMISP object edit authorization bypass allows unauthorized sharing group assignmentEPSS 0.4%CVE-2026-95671MEDIUMMISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/addEPSS 0.4%CVE-2025-66384HIGHapp/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.EPSS 0.4%CVE-2026-85547MEDIUMCross-Site Request Forgery via Attacker-Controlled REST Detection in MISPEPSS 0.4%CVE-2026-10611HIGHOTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabledEPSS 0.4%CVE-2026-91846HIGHMISP Collection Element Add Missing Authorization on Referenced Object UUIDEPSS 0.4%CVE-2026-94394MEDIUMMISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object ReferencesEPSS 0.4%CVE-2026-91851MEDIUMMISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in Permission Flag ComparisonEPSS 0.4%CVE-2026-54360HIGHMISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groupsEPSS 0.4%CVE-2026-54397MEDIUMMISP event editing allows unauthorized assignment to undisclosed sharing groupsEPSS 0.4%CVE-2026-95685MEDIUMMISP Missing Authorization on replaceSuggestionInReport Event Report ActionEPSS 0.4%CVE-2026-73155MEDIUMcti-transmute Missing Authorization Allows Reactions to Private CommentsEPSS 0.4%CVE-2026-60125MEDIUMimportModule function in MISP ignores per-organisation import module restrictionsEPSS 0.4%CVE-2026-88915HIGHMISP Event Template Instantiation Bypasses Sharing Group and Tagging AuthorizationEPSS 0.4%CVE-2026-73140MEDIUMcti-transmute Evaluation Report Exports Expose Private Comments and Author InformationEPSS 0.4%CVE-2026-54362MEDIUMMISP template builder exposes non-visible custom galaxies across organisationsEPSS 0.4%CVE-2026-86342MEDIUMMISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed InformationEPSS 0.3%CVE-2026-86408HIGHMISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected EventsEPSS 0.3%