CVE-2026-106513 Details
Description
MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the download_attachments_on_load setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection.
A remote code execution vulnerability has been identified in MISP, specifically in the handling of Redis host settings for the core application and certain plugins. This issue affects site-admin users who can access the web UI or API. The vulnerability arises because background job workers trust raw Redis job payloads without proper validation. An attacker who compromises a site-admin session, potentially through a stored cross-site scripting vulnerability, can manipulate the Redis host settings to point to an attacker-controlled Redis server. After redirecting the Redis connection, the attacker can inject malicious job payloads that the workers execute, leading to arbitrary command execution as the worker account. Furthermore, the vulnerability allows modification of the download_attachments_on_load setting, which controls inline attachment rendering, potentially facilitating additional client-side attacks.
The vulnerability has been addressed by updating the Redis host settings to be command-line interface only, preventing modifications through the web UI or API. Additionally, the download_attachments_on_load setting has been locked to prevent unauthorized changes. Users should update to the latest version of MISP where this fix has been implemented.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 6, 2026CISA-ADP
Assessed Oct 7, 2026Supplier
Assessed Oct 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/MISP/commit/2ebf29f93 | CIRCL | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CIRCL |
| CWE-749 | Exposed Dangerous Method or Function | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| MISP | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 7, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2026 | CVE Modified | CIRCL |
| Oct 6, 2026 | New CVE Received | CIRCL |
Volerion