PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77710 MISP CVE debrief

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection.

Vendor
MISP
Product
misp-stix
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-26
Advisory published
2026-08-21
Advisory updated
2026-08-26

Who should care

Organizations using misp-stix should be aware of this vulnerability and take necessary actions to prevent potential security risks. Affected operators should review their deployments and ensure that the patch is applied to prevent potential security risks. Platform administrators should verify that the patch is applied and monitor for suspicious STIX document imports. Vulnerability management teams should prioritize patching and verify the integrity of MISP attribute metadata. Security teams should review and apply the patch to prevent potential security risks and monitor for suspicious activity. Additionally, organizations should verify the integrity of MISP attribute metadata and monitor for suspicious STIX document imports to prevent potential security risks. This vulnerability could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import, potentially causing information to be shared contrary to the importing organization's policy or influencing downstream processing and automation based on attacker-controlled tags or metadata. Therefore, it is essential for organizations to prioritize patching and take necessary actions to prevent potential security risks. The vulnerability results from dynamically assigning externally supplied object properties without restricting them to an expected set of attributes, matching CWE-915. MITRE specifically describes this weakness as accepting externally influenced fields without controlling which object attributes may be modified and recommends an allow-list, which is the approach implemented by the patch. The attack is also consistent with CAPEC-153 (Input Data Manipulation), in which an attacker controls the structure or flags of supplied data so that the target selects a different processing path or interprets the content differently than intended. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified

Technical summary

The vulnerability results from dynamically assigning externally supplied object properties without restricting them to an expected set of attributes, matching CWE-915. The attack is also consistent with CAPEC-153 (Input Data Manipulation), in which an attacker controls the structure or flags of supplied data so that the target selects a different processing path or interprets the content differently than intended.

Defensive priority

Organizations using misp-stix should prioritize patching to prevent potential security risks.

Recommended defensive actions

  • Review and apply the patch to prevent potential security risks
  • Verify the integrity of MISP attribute metadata
  • Monitor for suspicious STIX document imports
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability results from dynamically assigning externally supplied object properties without restricting them to an expected set of attributes, matching CWE-915. MITRE specifically describes this weakness as accepting externally influenced fields without controlling which object attributes may be modified and recommends an allow-list, which is the approach implemented by the patch.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77710 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77710

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77710 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77710

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/misp-stix/commit/3e5e7bda

    5a6e4751-2f3f-4070-9419-94fb35b644e8

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/misp-stix/commit/66c654b9

    5a6e4751-2f3f-4070-9419-94fb35b644e8

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.