PatchSiren cyber security CVE debrief
CVE-2026-44379 MISP CVE debrief
CVE-2026-44379 is a medium-severity vulnerability in MISP Collections that did not enforce RFC 4122 UUID validation on the uuid field prior to version 2.5.37. This oversight allowed users with the ability to create or modify Collection records to submit malformed UUID values, potentially causing integrity issues or unexpected behavior in code paths that assume Collection UUIDs are valid identifiers. The vulnerability was fixed in version 2.5.37. Defenders should assess their exposure and prioritize patching to limit the risk of exploitation.
- Vendor
- MISP
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-06-22
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-06-22
Who should care
Defenders responsible for MISP installations, particularly those with user access to create or modify Collection records, should prioritize patching to version 2.5.37 or later. This vulnerability, while not highly severe, could lead to integrity issues or unexpected behavior if exploited. Reviewing user access controls and ensuring proper validation of UUIDs in MISP Collections is crucial.
Technical summary
The vulnerability (CVE-2026-44379) exists in MISP Collections due to a lack of RFC 4122 UUID validation on the uuid field in versions prior to 2.5.37. This allows users with create or modify permissions on Collection records to submit malformed UUIDs, potentially causing system instability or unexpected behavior. The issue is addressed in MISP version 2.5.37, which enforces proper UUID validation.
Defensive priority
Medium priority due to potential for integrity issues and unexpected behavior with user-level access
Recommended defensive actions
- Inventory MISP installations and identify versions prior to 2.5.37
- Review user access controls for MISP Collections and restrict create/modify permissions as needed
- Apply the patch to upgrade MISP to version 2.5.37 or later
- Verify UUID validation is properly enforced post-patching
- Monitor for unusual activity or errors related to Collection UUIDs
Evidence notes
The CVE-2026-44379 vulnerability was publicly disclosed on May 13, 2026, and details were last modified on June 22, 2026. The vulnerability affects MISP versions prior to 2.5.37. Primary evidence includes the official CVE record and details from the NVD. Defenders should verify MISP version and user access controls, and review official advisories for additional information.
Official resources
-
CVE-2026-44379 CVE record
CVE.org
-
CVE-2026-44379 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
This article is AI-assisted and based on the supplied source corpus.