Junglewise Threat Intelligence

CVE-2026-94401: MISP file upload SSRF and arbitrary file read

CVE-2026-94401 · Severity: info · Published 2026-09-21

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP, a threat intelligence sharing platform, contains a file upload vulnerability affecting users with data modification permissions. An authenticated attacker could upload a specially crafted file to make the server read local files or make requests to internal services, potentially exposing sensitive information or allowing lateral movement within the network.

Technical details

The vulnerability exists in MISP's XML import function (addMISPExportFile), which did not validate that uploaded files contained actual XML before processing them. An authenticated user with modify permissions could upload a file containing a local file path (e.g., /tmp/sensitive.xml) or internal URL (e.g., http://10.0.0.1/) instead of valid XML, causing MISP to read the local file or make an SSRF request. The fix disables the readFile option and validates that the content contains a proper XML document before parsing.

Affected products

  • MISP Project MISP before 2.5.47

Timeline

  • 2026-09-21: disclosed

References

Related threats