Junglewise Threat Intelligence

CVE-2026-85236: MISP cross-site request forgery in cullEmptyEvents

CVE-2026-85236 · Severity: high · CVSS 8.8 · Published 2026-09-03

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is an open-source threat intelligence platform used by security teams to track and share malware and cyber threats. A CSRF vulnerability in the event deletion function allowed attackers to trick authenticated administrators into permanently deleting event records via a malicious link or embedded image—without the administrator's knowledge or consent. The deleted events bypass blocklists, making them unrecoverable and potentially enabling untracked re-synchronization of threat data.

Technical details

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP's EventsController. The endpoint performed state-changing and irreversible deletion of published empty events while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF token validation, an attacker could cause an authenticated user with sufficient privileges to invoke the endpoint by embedding a crafted URL (e.g., in an image tag or redirect). Exploitation triggers permanent deletion of MISP event records using skipBlocklist, preventing blocklist entries that would normally track or prevent subsequent synchronization. The vulnerability was remediated by restricting cullEmptyEvents to HTTP POST requests, ensuring CakePHP's CSRF protections are applied.

Affected products

  • MISP Project MISP

Timeline

  • 2026-09-03: disclosed: Published on NVD
  • 2026-09: patched: Fix committed to require POST for cullEmptyEvents action

References