Junglewise Threat Intelligence

CVE-2026-86440: MISP dashboard widget stored XSS via insufficient URL validation

CVE-2026-86440 · Severity: medium · CVSS 5.4 · Published 2026-09-07

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is an open-source threat intelligence platform used by organizations to share and analyze security events. Dashboard widgets in affected versions allow users to configure URLs (e.g., in the Button widget), but the system fails to properly validate these URLs. An attacker with user access can inject javascript: URLs or other dangerous schemes that execute malicious code or redirect other users to attacker-controlled sites when they interact with the widget, compromising the integrity of the threat intelligence platform and potentially exposing sensitive data.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in MISP's dashboard widget URL handling. The Button widget accepted user-controlled URLs and attempted validation by checking only whether the parsed hostname matched the configured MISP hostname, failing to reject dangerous URL schemes (javascript:) and alternative URL forms (backslash-based authority) that browsers normalize differently than PHP's URL parser. An authenticated user can inject malicious URLs in widget configuration; when another user renders the dashboard, the unsafe URL reaches the generated anchor's href attribute and executes in the victim's browser context. The fix implements a shared DashboardURLValidator that rejects dangerous schemes, raw backslashes, control characters, and unauthorized origins, validating URLs at both widget handler and renderer stages. Patch is available in the upstream repository.

Affected products

  • MISP Project MISP ≤2.5.45

Timeline

  • 2026-09-07: disclosed: CVE-2026-86440 published
  • 2026-08-25: patched: Fix committed to upstream repository (commit adf704e94)

References