These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An authorization flaw in MISP's correlation handling during attribute searches allows an authenticated user to retrieve attributes and event details belonging to events they no longer have permission to view. This issue affects MISP prior to v2.5.48. The flaw arises from the system using a stale distribution snapshot stored on the correlation row rather than the live event access control list. As a result [truncated]
CVE-2026-104910 debrief based on the supplied source corpus. MISP contains an authorization bypass in the related events listing functionality, allowing unauthorized disclosure of event metadata. The vulnerability affects MISP versions prior to the fix commit (2ffa97f05). Defenders should care about CVE-2026-104910 because it allows unauthorized access to sensitive event metadata in MISP instances, potent [truncated]
CVE-2026-97863 is a vulnerability in the cisco_firesight_manager_ACL_rule_export module in misp-modules. The module generates a shell script that interpolates configuration values and MISP attribute values directly into single-quoted shell string assignments without escaping or sanitization. This allows an attacker to inject arbitrary shell commands into the exported script, potentially exposing fireSIGHT [truncated]
CVE-2026-94277 is a medium-severity vulnerability in MISP's galaxy matrix statistics view. An authenticated user with the perm_galaxy_editor permission can create or modify a galaxy with a name containing arbitrary HTML or JavaScript, which is then executed in the browser context of any user who opens the galaxy matrix statistics page. This enables session hijacking, credential theft, data exfiltration, o [truncated]
A stored cross-site scripting (XSS) vulnerability exists in the Overmind theme's statistics views of MISP. The vulnerability allows an attacker with low-level authenticated access to create or rename an object whose name is rendered in the legend, potentially leading to session hijacking, data exfiltration, or arbitrary actions performed on behalf of the victim when another user views the affected Overmind dashboard.
CVE-2026-93295 debrief based on the supplied source corpus. The MISP background job dispatch mechanism vulnerability allows remote code execution as the web user. An attacker can submit a crafted contact form to execute PHP code with the privileges of the web user. Defenders should assess exposure, prioritize remediation, and implement compensating controls to prevent exploitation. This vulnerability requ [truncated]
A logic error in the MISP sachertortephp library's Xml::build() method allows for Server-Side Request Forgery (SSRF) with an information-disclosure impact. The vulnerability occurs when the readFile option is set to false, and an attacker can influence the input parameter to trigger an outbound HTTPS request to an attacker-controlled or internal URL.
CVE-2026-86452 is a vulnerability in MISP that allows unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format. This issue was fixed by adding a maximum email input length of 1024 [truncated]
CVE-2026-86451 is a medium-severity vulnerability in MISP that allows authenticated users to access object-reference records without proper authorization. This could potentially expose sensitive information. The vulnerability affects MISP versions ≤2.5.45 and has a CVSS score of 5.3. A fix is available in later versions. The vulnerability allows authenticated users to retrieve object-reference records by [truncated]
CVE-2026-86441 debrief based on the supplied source corpus. Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authenticated users without the perm_sharing_group permission could enumerate organisations even though the [truncated]
The CVE-2026-86440 vulnerability affects MISP dashboard widget URL validation, allowing for stored XSS attacks. The vulnerability exists in versions ≤2.5.45 and is caused by insufficient validation of URLs used by dashboard widgets, particularly the Button widget. The fix routes widget URLs through a shared DashboardURLValidator, rejects dangerous schemes, raw backslashes, control characters, and unauthor [truncated]
CVE-2026-86419 debrief based on CVE Program and NVD records. The vulnerability affects MISP versions ≤2.5.45, allowing for potential credential exposure, internal network resource access, and other security risks due to insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. The fix adds redirect validation, blocks internal destinations for cr [truncated]
CVE-2026-86418 debrief based on the supplied source corpus. Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The fix calls Organisation::createConditions($this->Auth->user()) and appends the resulting ACL conditions to the picker query. Ordi [truncated]
CVE-2026-86417 debrief based on the supplied source corpus. MISP versions ≤2.5.45 have an inconsistent enforcement of email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw redacted data in the normal HTML interface could request the REST/JSO [truncated]
CVE-2026-86408 debrief based on the supplied source corpus. Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields. The fix adds parent_id and parent_type to the lookup and then enforces authorization through [truncated]
CVE-2026-86351 debrief based on CVE Program and NVD records. The vulnerability in MISP allows attackers to redirect users to external origins after login, potentially leading to phishing or further exploitation. Defenders should prioritize verifying MISP installations for version 2.5.45 or later, especially if user-configurable homepages are used. The fix introduces a shared InternalRedirectValidator that [truncated]
CVE-2026-86347 allows low-privileged users in MISP to upload files without proper restrictions, potentially consuming server disk space. The issue arises from a misconfigured ACL entry for templates/uploadFile, which was set to '*' instead of 'perm_add'. This vulnerability can be exploited by low-privileged or read-only users, who can repeatedly upload files and consume server disk space without requiring [truncated]
CVE-2026-86342 debrief based on CVE Program and NVD records. Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality, potentially exposing restricted event correlations and associated event information. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. MISP users and administrators should assess exposure and prioritize patchi [truncated]
A critical vulnerability was discovered in MISP's LDAP and LinOTP authentication components. An attacker can bypass authentication by exploiting insufficient validation of user-supplied credentials, potentially allowing them to impersonate existing MISP users, including those with administrative privileges. This authentication bypass could enable unauthorized access to sensitive threat-intelligence data, [truncated]
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser components maintained per-document state that was not completely cleared between conversions. This issue primarily affects application [truncated]
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loading failures. Because SystemExit inherits from BaseException rather than Exception, these failures bypassed the exception handlers used by callers of the library. As a result, a malformed STIX document could ter [truncated]
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T10:17:13.180Z and has not been modified since then. The vulnerability affects MISP cti-transmute, exposing state-changing account operations as GET requests, making them susceptible to cross-site request forgery. The patch converts these actions to POST or DELETE and adds CSRF protection. Defende [truncated]
The CVE-2026-73161 vulnerability affects cti-transmute, allowing malicious markup injection through the search highlighting feature. The fix introduces a shared highlightMatches() helper that escapes special characters before inserting <mark> elements. Organizations using cti-transmute should review and update their installations to ensure the fix is applied. This involves validating affected scope, sever [truncated]
The cti-transmute library contains an SSRF vulnerability in its /fetch_misp_event and /misp_search_events endpoints. This vulnerability allows attackers to make internal network requests by not properly resolving hostnames during URL validation. The fix involves resolving hostnames using socket.getaddrinfo() and checking for global routability. Users of the library, especially those with internal networks [truncated]
The cti-transmute library, used for threat intelligence data transformation, is vulnerable to cross-site scripting (XSS) attacks. This vulnerability arises from the improper handling of user-supplied icon values, which can be interpolated into HTML. An attacker could craft a malicious icon value to inject attacker-controlled HTML, potentially leading to XSS attacks when the affected tag is rendered. The v [truncated]
The CVE record describes a vulnerability in cti-transmute where remote MISP instance data is rendered into the event-browser interface using HTML interpolation. Malicious or compromised remote instances could inject HTML or script-capable content. The patch addresses this by ensuring remote-derived values do not reach innerHTML and restricts tag colors to six-digit hexadecimal values.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T08:17:21.323Z and has not been modified since then. The vulnerability affects cti-transmute, specifically versions that fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. This allows for potential XSS attacks through malicious STIX or MISP data [truncated]
The CVE-2026-73155 vulnerability affects cti-transmute, allowing authenticated users to add or remove emoji reactions on comments without proper authorization checks. This could lead to unauthorized access to sensitive information. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of cti-transmute, administrators of comment-based systems, and security teams should be aw [truncated]
The cti-transmute library failed to apply comment-level access-control rules when generating evaluation report exports. This could allow a user authorized to view a conversion to export its evaluation report and obtain private evaluation comments meant for the conversion owner, comment author, or administrators. The issue is resolved by filtering comments based on user permissions. Affected product deploy [truncated]