CVE-2026-94404 Details
Description
MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because of this, an attacker could create a malicious webpage that silently sends a request to MISP when visited by an authenticated user. If successful, the attacker could change details of an attribute, such as its value, type, category, comment, distribution settings, or related timestamps. The attack requires the victim to already be logged in to MISP and to visit an attacker-controlled page. The main impact is unauthorized modification of threat-intelligence data, which could lead to incorrect indicators, wrong classifications, or altered sharing settings and reduce confidence in the accuracy of the information stored in MISP. Version affected: <2.5.47
A cross-site request forgery (CSRF) vulnerability has been identified in MISP versions prior to 2.5.47. This issue allows an attacker to manipulate threat intelligence data through the browser of a logged-in user, without the user's consent. The vulnerability arises because the affected function failed to properly implement MISP's standard protections against forged requests. As a result, an attacker could craft a malicious webpage that, when visited by an authenticated user, silently transmits a request to MISP using the user's session cookie. If successful, this could lead to unauthorized changes in attribute details, such as value, type, category, comment, distribution settings, or timestamps. The primary impact is the incorrect modification of threat intelligence data, potentially causing misleading indicators, erroneous classifications, or altered sharing settings, thereby undermining trust in the accuracy of information within MISP.
Users can update to MISP version 2.5.47 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/MISP/commit/dfbae33f9 | CIRCL | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| MISP | < 2.5.47 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | CIRCL |
Volerion