Junglewise Threat Intelligence

CVE-2026-86351: MISP open redirect via insufficient homepage validation

CVE-2026-86351 · Severity: medium · CVSS 6.1 · Published 2026-09-07

Technologies: Misp. Vendors: Misp.

Executive brief

MISP is a threat intelligence platform used by organizations to share and analyze security information. The application allows users to configure a custom homepage URL that is used for post-login redirection. A flaw in the URL validation logic permitted attackers to craft protocol-relative URLs (e.g., //attacker.example) that bypass the check, causing the application to redirect users to external attacker-controlled sites after login, enabling phishing or session hijacking attacks.

Technical details

The vulnerability is an open redirect in the homepage setting validation. MISP validated user-configurable homepage paths by checking only whether they began with a forward slash (/), which is insufficient because protocol-relative URLs like //attacker.example also start with / but resolve to an external origin in browsers. The vulnerable homepage value is stored in user settings and later retrieved by post-login routing logic, which emits the unvalidated path to the Location HTTP header. The fix implements a comprehensive InternalRedirectValidator that rejects URLs containing a host, scheme, userinfo, unsafe leading sequences (//, /\), malformed URLs, and control characters, with revalidation on read to catch legacy unsafe values.

Affected products

  • MISP MISP ≤2.5.45

Timeline

  • 2026-09-07: disclosed: Published on NVD
  • 2026-08-26: patched: Fix committed to repository

References

Related threats