Junglewise Threat Intelligence

CVE-2026-95693: MISP EventReport path traversal information disclosure

CVE-2026-95693 · Severity: info · Published 2026-09-22

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP, a threat intelligence platform, contains a vulnerability in its EventReport upload functionality where an authenticated user with basic permissions can enumerate files on the server by supplying arbitrary filesystem paths. The application returns distinct error messages revealing whether files exist and their type, allowing attackers to map the server's filesystem without reading actual file contents. This information disclosure can identify sensitive locations like configuration files or private keys that could be targeted in follow-up attacks.

Technical details

The EventReport::uploadPicture method processes a caller-supplied tmp_name field and invokes file_exists(), mime_content_type(), and exif_imagetype() before validating with is_uploaded_file(). An authenticated perm_add user can supply arbitrary filesystem paths, and distinct validation error messages leak file existence and type information. The vulnerability does not allow file read/write or code execution, but enables information disclosure through error-based enumeration.

Affected products

  • MISP Project MISP

Timeline

  • 2026-09-22: disclosed
  • 2026-09-22: patched: Fix applied in commit 9a2a4ac to reject forged upload paths

References

Related threats