Junglewise Threat Intelligence

CVE-2026-90893: MISP Cross-Site Request Forgery in user settings

CVE-2026-90893 · Severity: info · Published 2026-09-14

Technologies: Misp. Vendors: Misp.

Executive brief

MISP is a threat intelligence sharing platform used by organizations to collaboratively manage and share threat data. A CSRF vulnerability in the user settings controller allows an attacker to forge requests that change a logged-in user's preferences—including their default homepage URL, visual theme, and event index columns—by tricking the user into visiting a malicious webpage. The most serious impact is redirecting the user's landing page to an attacker-controlled URL for phishing or further compromise.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) in MISP's UserSettingsController affecting the setTheme, setHomePage, and eventIndexColumnToggle actions. These endpoints were explicitly added to the Security component's unlockedActions list, disabling both CSRF token and field-hash validation. The actions accept POST requests and modify per-user application state without CSRF protection. An attacker can craft a malicious page (link, image, or auto-submitting form) that, when loaded by an authenticated MISP user, forges requests to alter the victim's settings. No authentication bypass is required; the victim must already be logged in. A patch is available in commit 979337b restoring CSRF validation to these endpoints.

Affected products

  • MISP MISP ≤2.5.45

Timeline

  • 2026-09-14: disclosed
  • 2026: patched: Fix available in commit 979337b

References

Related threats