Vulnerabilities in misp
145 resultsVexday analysis
MISP apresenta 37 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 5 classificadas como críticas (CVSS alto). Não há registros de exploração ativa em campo (KEV), mas o volume recente e a dominância de falhas de autorização (CWE-863) indicam exposição significativa em ambientes de compartilhamento de inteligência de ameaças. Recomenda-se priorizar patches críticos e revisar controles de acesso.
CVE-2026-85238HIGHSession Fixation in MISP CustomAuth Authentication Allows Session HijackingEPSS 0.3%CVE-2025-67906MEDIUMIn MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.EPSS 0.3%CVE-2026-97863MEDIUMmisp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute ValuesEPSS 0.3%CVE-2025-66386MEDIUMapp/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.EPSS 0.3%CVE-2026-9136HIGHUnauthorized ShadowAttribute modification in MISP via client-supplied identifierEPSS 0.3%CVE-2026-44379MEDIUMMISP: Improper UUID validation in MISP CollectionsEPSS 0.3%CVE-2026-85230MEDIUMMISP Dashboard Button Widget Allows Persistent JavaScript URL InjectionEPSS 0.3%CVE-2026-86441LOWMISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation DataEPSS 0.3%CVE-2026-85221HIGHMISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle AttacksEPSS 0.3%CVE-2026-86418LOWMISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized UsersEPSS 0.3%CVE-2026-86417MEDIUMMISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized UsersEPSS 0.3%CVE-2026-69082HIGHCross-Site Request Forgery in the Administrative User Deletion EndpointEPSS 0.3%CVE-2026-86451MEDIUMMISP Event Graph Object Reference Lookup Exposes References from Unauthorized ObjectsEPSS 0.3%CVE-2026-54359HIGHMISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by defaultEPSS 0.3%CVE-2026-95658MEDIUMMISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-site execution of workflow modulesEPSS 0.3%CVE-2026-90893MEDIUMMISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, and eventIndexColumnToggle EndpointsEPSS 0.3%CVE-2026-86351MEDIUMMISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URLEPSS 0.3%CVE-2024-57969MEDIUMapp/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.EPSS 0.3%CVE-2026-85226MEDIUMMISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted CorrelationsEPSS 0.3%CVE-2026-85227MEDIUMReflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes ParametersEPSS 0.3%