Junglewise Threat Intelligence

CVE-2026-67178: MISP installation scripts open redirect in Apache configuration

CVE-2026-67178 · Severity: info · CVSS 7.8 · Published 2026-07-28

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

A vulnerability in the MISP installation scripts could allow attackers to redirect users from the legitimate MISP platform to malicious websites. This occurs because the automated setup for the Apache web server incorrectly handles the transition from insecure (HTTP) to secure (HTTPS) connections. Attackers could exploit this to conduct phishing attacks or steal user credentials by tricking victims into visiting a fake login page that appears to be hosted on the trusted domain.

Technical details

An open redirect vulnerability exists in MISP due to a misconfiguration in the Apache virtual-host files generated by installation scripts. The 'Redirect permanent' directive lacks a trailing slash on the destination URL (e.g., 'Redirect permanent / https://misp.example'). Because Apache appends the remaining request path to the destination, a specially crafted URL like 'http://misp.example/@attacker.com' results in a redirect to 'https://misp.example@attacker.com', which browsers interpret as the domain 'attacker.com' with 'misp.example' as userinfo. This can be exploited by unauthenticated remote attackers to facilitate phishing or credential theft. The issue is fixed in version 2.5.41 by adding the missing trailing slash to the redirect destination.

Affected products

  • MISP Project MISP < 2.5.41

Timeline

  • 2026-07-28: advisory: NVD publication date
  • 2026-07-28: disclosed: Initial disclosure by CIRCL

References