Executive brief
MISP, an open-source threat intelligence platform, contains a configuration flaw where a security check for web requests is disabled by default. This could allow an attacker to trick a logged-in user into unknowingly performing actions, such as modifying or deleting threat data, by visiting a malicious website. While the issue can be fixed by enabling a specific security setting, organizations using multiple web addresses for a single MISP instance should test the change to ensure it does not disrupt legitimate access.
Technical details
MISP is vulnerable to Cross-Site Request Forgery (CSRF) due to an insecure default initialization of the 'Security.check_sec_fetch_site_header' setting. When disabled, the application fails to validate the browser-provided 'Sec-Fetch-Site' header for state-changing requests (POST, PUT, AJAX). A remote unauthenticated attacker can exploit this by inducing an authenticated user to visit a malicious site that triggers forged requests to MISP automation endpoints. This can result in unauthorized data modification or configuration changes. A patch has been introduced to warn administrators of this setting, and mitigation involves manually enabling the header check, though this may impact multi-homed deployments.
Affected products
- MISP Project MISP All versions prior to commit b82db1b
Timeline
- 2026-06-12: disclosed: CVE-2026-54359 published
- 2026-06-12: patched: Commit b82db1b added security warnings for the insecure default setting