{"schema_version":1,"title":"Misp vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 47 vulnerabilities in Misp: 10 in the last 7 days and 38 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-95805, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/misp","json_url":"https://junglewise.ai/threats/technologies/misp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/misp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":47,"critical":1,"exploited":0,"last_7_days":10,"last_30_days":35,"last_90_days":38,"last_365_days":47},"latest":[{"cve":"CVE-2026-95805","epss":0.0041,"slug":"cve-2026-95805-a-typo-in-the-misp-aclcomponent-access-control-configuration","title":"MISP ACL configuration typo in previewEventAttributes","severity":"info","exploited":false,"published_at":"2026-09-22T16:18:24.29+00:00","url":"https://junglewise.ai/threats/cve-2026-95805-a-typo-in-the-misp-aclcomponent-access-control-configuration"},{"cve":"CVE-2026-95703","epss":0.0051,"slug":"cve-2026-95703-in-misp-the-organisationscontroller-uploadlogo-method-processed-a","title":"MISP OrganisationsController file-existence oracle in logo upload","severity":"info","exploited":false,"published_at":"2026-09-22T15:17:28.323+00:00","url":"https://junglewise.ai/threats/cve-2026-95703-in-misp-the-organisationscontroller-uploadlogo-method-processed-a"},{"cve":"CVE-2026-95698","epss":0.0072,"slug":"cve-2026-95698-the-findorgimage-method-in-misp-s-orgimghelper-constructs-a","title":"MISP OrgImgHelper path traversal in findOrgImage","severity":"info","exploited":false,"published_at":"2026-09-22T15:17:27.887+00:00","url":"https://junglewise.ai/threats/cve-2026-95698-the-findorgimage-method-in-misp-s-orgimghelper-constructs-a"},{"cve":"CVE-2026-95697","epss":0.0038,"slug":"cve-2026-95697-misp-contains-an-authorization-flaw-in-the-organisation-model-s","title":"MISP authorization flaw in captureOrg method","severity":"info","exploited":false,"published_at":"2026-09-22T15:17:27.67+00:00","url":"https://junglewise.ai/threats/cve-2026-95697-misp-contains-an-authorization-flaw-in-the-organisation-model-s"},{"cve":"CVE-2026-95682","epss":0.0042,"slug":"cve-2026-95682-misp-contains-a-stored-cross-site-scripting-xss-vulnerability-in","title":"MISP stored XSS in admin email composition screen","severity":"info","exploited":false,"published_at":"2026-09-22T14:17:22.627+00:00","url":"https://junglewise.ai/threats/cve-2026-95682-misp-contains-a-stored-cross-site-scripting-xss-vulnerability-in"},{"cve":"CVE-2026-95659","epss":0.0039,"slug":"cve-2026-95659-misp-contains-a-reflected-cross-site-scripting-xss-vulnerability","title":"MISP reflected XSS in AnalystDataController viewForObject","severity":"info","exploited":false,"published_at":"2026-09-22T13:17:13.797+00:00","url":"https://junglewise.ai/threats/cve-2026-95659-misp-contains-a-reflected-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2026-95658","epss":0.0027,"slug":"cve-2026-95658-misp-s-workflowscontroller-exposed-the-modulestatelessexecution","title":"MISP WorkflowsController CSRF vulnerability in moduleStatelessExecution","severity":"info","exploited":false,"published_at":"2026-09-22T13:17:13.577+00:00","url":"https://junglewise.ai/threats/cve-2026-95658-misp-s-workflowscontroller-exposed-the-modulestatelessexecution"},{"cve":"CVE-2026-94393","epss":0.0037,"slug":"cve-2026-94393-when-a-user-creates-or-edits-a-report-inside-an-event-misp-can","title":"MISP event report access control bypass via UUID","severity":"info","exploited":false,"published_at":"2026-09-21T14:17:30.5+00:00","url":"https://junglewise.ai/threats/cve-2026-94393-when-a-user-creates-or-edits-a-report-inside-an-event-misp-can"},{"cve":"CVE-2026-94379","epss":0.0058,"slug":"cve-2026-94379-the-login-function-in-misp-s-userscontroller-php-contained","title":"MISP HTTP method validation bypass in login function","severity":"info","exploited":false,"published_at":"2026-09-21T13:17:13.2+00:00","url":"https://junglewise.ai/threats/cve-2026-94379-the-login-function-in-misp-s-userscontroller-php-contained"},{"cve":"CVE-2026-94373","epss":0.0039,"slug":"cve-2026-94373-misp-contains-a-dom-based-cross-site-scripting-xss-vulnerability","title":"MISP DOM-based XSS in contextual menu component","severity":"info","exploited":false,"published_at":"2026-09-21T13:17:12.757+00:00","url":"https://junglewise.ai/threats/cve-2026-94373-misp-contains-a-dom-based-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2026-93296","epss":0.0039,"slug":"cve-2026-93296-misp-overmind-stored-cross-site-scripting-in-statistics-views","title":"MISP Overmind stored cross-site scripting in statistics views","severity":"info","exploited":false,"published_at":"2026-09-17T17:18:17.28+00:00","url":"https://junglewise.ai/threats/cve-2026-93296-misp-overmind-stored-cross-site-scripting-in-statistics-views"},{"cve":"CVE-2026-92003","epss":0.0057,"slug":"cve-2026-92003-misp-authentication-failure-logging-bypass","title":"MISP authentication-failure logging bypass","severity":"info","exploited":false,"published_at":"2026-09-15T12:17:55.757+00:00","url":"https://junglewise.ai/threats/cve-2026-92003-misp-authentication-failure-logging-bypass"},{"cve":"CVE-2026-92002","epss":0.0053,"slug":"cve-2026-92002-misp-redis-unavailability-silences-authentication-failure-logging","title":"MISP Redis unavailability silences authentication failure logging","severity":"info","exploited":false,"published_at":"2026-09-15T12:17:55.557+00:00","url":"https://junglewise.ai/threats/cve-2026-92002-misp-redis-unavailability-silences-authentication-failure-logging"},{"cve":"CVE-2026-91859","epss":0.0047,"slug":"cve-2026-91859-misp-access-log-corruption-on-request-exceptions","title":"MISP access log corruption on request exceptions","severity":"info","exploited":false,"published_at":"2026-09-15T10:17:06.47+00:00","url":"https://junglewise.ai/threats/cve-2026-91859-misp-access-log-corruption-on-request-exceptions"},{"cve":"CVE-2026-91857","cvss":4.3,"epss":0.0021,"slug":"cve-2026-91857-misp-state-changing-actions-missing-post-requirement","title":"MISP state-changing actions missing POST requirement","severity":"info","exploited":false,"published_at":"2026-09-15T10:17:06.267+00:00","url":"https://junglewise.ai/threats/cve-2026-91857-misp-state-changing-actions-missing-post-requirement"},{"cve":"CVE-2026-91825","epss":0.0039,"slug":"cve-2026-91825-misp-authorization-bypass-in-event-sharing-group-assignment","title":"MISP authorization bypass in event sharing group assignment","severity":"info","exploited":false,"published_at":"2026-09-15T09:16:45.54+00:00","url":"https://junglewise.ai/threats/cve-2026-91825-misp-authorization-bypass-in-event-sharing-group-assignment"},{"cve":"CVE-2026-90957","cvss":6.5,"epss":0.004,"slug":"cve-2026-90957-misp-stored-cross-site-scripting-in-inline-svg-images","title":"MISP stored cross-site scripting in inline SVG images","severity":"info","exploited":false,"published_at":"2026-09-14T13:19:32.907+00:00","url":"https://junglewise.ai/threats/cve-2026-90957-misp-stored-cross-site-scripting-in-inline-svg-images"},{"cve":"CVE-2026-90955","epss":0.0016,"slug":"cve-2026-90955-misp-interactive-cli-shell-audit-logging-user-attribution-loss","title":"MISP interactive CLI shell audit logging user attribution loss","severity":"info","exploited":false,"published_at":"2026-09-14T13:19:32.583+00:00","url":"https://junglewise.ai/threats/cve-2026-90955-misp-interactive-cli-shell-audit-logging-user-attribution-loss"},{"cve":"CVE-2026-90895","cvss":0,"epss":0.0015,"slug":"cve-2026-90895-misp-interactive-cli-shell-authorization-bypass","title":"MISP interactive CLI shell authorization bypass","severity":"info","exploited":false,"published_at":"2026-09-14T10:17:06.27+00:00","url":"https://junglewise.ai/threats/cve-2026-90895-misp-interactive-cli-shell-authorization-bypass"},{"cve":"CVE-2026-90893","epss":0.0026,"slug":"cve-2026-90893-misp-cross-site-request-forgery-in-user-settings","title":"MISP Cross-Site Request Forgery in user settings","severity":"info","exploited":false,"published_at":"2026-09-14T10:17:05.93+00:00","url":"https://junglewise.ai/threats/cve-2026-90893-misp-cross-site-request-forgery-in-user-settings"},{"cve":"CVE-2026-88915","cvss":0,"epss":0.0035,"slug":"cve-2026-88915-misp-event-template-authorization-bypass-in-sharing-group-and","title":"MISP event template authorization bypass in sharing group and tagging","severity":"info","exploited":false,"published_at":"2026-09-10T14:17:19.193+00:00","url":"https://junglewise.ai/threats/cve-2026-88915-misp-event-template-authorization-bypass-in-sharing-group-and"},{"cve":"CVE-2026-86452","cvss":7.5,"epss":0.0054,"slug":"cve-2026-86452-misp-denial-of-service-via-unbounded-email-input-on","title":"MISP denial-of-service via unbounded email input on unauthenticated endpoints","severity":"high","exploited":false,"published_at":"2026-09-07T14:16:56.833+00:00","url":"https://junglewise.ai/threats/cve-2026-86452-misp-denial-of-service-via-unbounded-email-input-on"},{"cve":"CVE-2026-86451","cvss":4.3,"epss":0.0027,"slug":"cve-2026-86451-misp-object-reference-authorization-bypass-in-eventgraphtool","title":"MISP object-reference authorization bypass in EventGraphTool","severity":"medium","exploited":false,"published_at":"2026-09-07T13:20:43.427+00:00","url":"https://junglewise.ai/threats/cve-2026-86451-misp-object-reference-authorization-bypass-in-eventgraphtool"},{"cve":"CVE-2026-86441","cvss":4.3,"epss":0.0028,"slug":"cve-2026-86441-misp-authorization-bypass-in-dashboard-widgets","title":"MISP authorization bypass in dashboard widgets","severity":"medium","exploited":false,"published_at":"2026-09-07T13:20:43.287+00:00","url":"https://junglewise.ai/threats/cve-2026-86441-misp-authorization-bypass-in-dashboard-widgets"},{"cve":"CVE-2026-86419","cvss":9.1,"epss":0.0042,"slug":"cve-2026-86419-misp-ssrf-and-credential-exposure-in-feed-retrieval-and-taxii","title":"MISP SSRF and credential exposure in feed retrieval and TAXII discovery","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:40.663+00:00","url":"https://junglewise.ai/threats/cve-2026-86419-misp-ssrf-and-credential-exposure-in-feed-retrieval-and-taxii"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":7},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":10}],"related":[],"technology":{"hub":true,"name":"Misp","slug":"misp","vendor":{"name":"Misp","slug":"misp","url":"https://junglewise.ai/threats/vendors/misp"},"aliases":[],"category":"threat-intelligence-platform","homepage":"https://www.misp-project.org/","repo_url":"https://github.com/MISP/MISP","description":"An open-source threat intelligence platform for sharing, storing and correlating indicators of compromise.","url":"https://junglewise.ai/threats/technologies/misp"},"most_severe":[{"cve":"CVE-2026-86419","cvss":9.1,"epss":0.0042,"slug":"cve-2026-86419-misp-ssrf-and-credential-exposure-in-feed-retrieval-and-taxii","title":"MISP SSRF and credential exposure in feed retrieval and TAXII discovery","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:40.663+00:00","url":"https://junglewise.ai/threats/cve-2026-86419-misp-ssrf-and-credential-exposure-in-feed-retrieval-and-taxii"},{"cve":"CVE-2026-85237","cvss":8.1,"epss":0.0046,"slug":"cve-2026-85237-misp-email-otp-brute-force-attack-in-authentication","title":"MISP email OTP brute-force attack in authentication","severity":"high","exploited":false,"published_at":"2026-09-03T16:18:27.163+00:00","url":"https://junglewise.ai/threats/cve-2026-85237-misp-email-otp-brute-force-attack-in-authentication"},{"cve":"CVE-2026-86452","cvss":7.5,"epss":0.0054,"slug":"cve-2026-86452-misp-denial-of-service-via-unbounded-email-input-on","title":"MISP denial-of-service via unbounded email input on unauthenticated endpoints","severity":"high","exploited":false,"published_at":"2026-09-07T14:16:56.833+00:00","url":"https://junglewise.ai/threats/cve-2026-86452-misp-denial-of-service-via-unbounded-email-input-on"},{"cve":"CVE-2026-44380","cvss":7.2,"epss":0.004,"slug":"cve-2026-44380-misp-improper-access-control-in-authentication-key-reset","title":"MISP improper access control in authentication key reset","severity":"high","exploited":false,"published_at":"2026-05-13T21:16:48.623+00:00","url":"https://junglewise.ai/threats/cve-2026-44380-misp-improper-access-control-in-authentication-key-reset"},{"cve":"CVE-2026-85238","cvss":6.8,"epss":0.0034,"slug":"cve-2026-85238-misp-session-fixation-vulnerability-in-customauth","title":"MISP session fixation vulnerability in CustomAuth","severity":"medium","exploited":false,"published_at":"2026-09-03T16:18:27.313+00:00","url":"https://junglewise.ai/threats/cve-2026-85238-misp-session-fixation-vulnerability-in-customauth"},{"cve":"CVE-2026-86347","cvss":6.5,"epss":0.0043,"slug":"cve-2026-86347-misp-acl-bypass-in-templatescontroller-uploadfile","title":"MISP ACL bypass in TemplatesController uploadFile","severity":"medium","exploited":false,"published_at":"2026-09-07T10:16:55.917+00:00","url":"https://junglewise.ai/threats/cve-2026-86347-misp-acl-bypass-in-templatescontroller-uploadfile"},{"cve":"CVE-2026-86351","cvss":6.1,"epss":0.0026,"slug":"cve-2026-86351-misp-open-redirect-via-insufficient-homepage-validation","title":"MISP open redirect via insufficient homepage validation","severity":"medium","exploited":false,"published_at":"2026-09-07T11:17:40.09+00:00","url":"https://junglewise.ai/threats/cve-2026-86351-misp-open-redirect-via-insufficient-homepage-validation"},{"cve":"CVE-2026-8080","cvss":5.4,"epss":0.0014,"slug":"cve-2026-8080-misp-stored-xss-in-template-element-attribute-handling","title":"MISP Stored XSS in template element attribute handling","severity":"medium","exploited":false,"published_at":"2026-05-07T12:16:18.467+00:00","url":"https://junglewise.ai/threats/cve-2026-8080-misp-stored-xss-in-template-element-attribute-handling"},{"cve":"CVE-2026-44381","cvss":5.3,"epss":0.0023,"slug":"cve-2026-44381-misp-sql-injection-in-event-and-shadow-attribute-listing","title":"MISP SQL injection in event and shadow attribute listing endpoints","severity":"medium","exploited":false,"published_at":"2026-05-13T21:16:48.77+00:00","url":"https://junglewise.ai/threats/cve-2026-44381-misp-sql-injection-in-event-and-shadow-attribute-listing"},{"cve":"CVE-2026-44379","cvss":5.3,"epss":0.0018,"slug":"cve-2026-44379-misp-improper-uuid-validation-in-collections","title":"MISP improper UUID validation in Collections","severity":"medium","exploited":false,"published_at":"2026-05-13T21:16:48.48+00:00","url":"https://junglewise.ai/threats/cve-2026-44379-misp-improper-uuid-validation-in-collections"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}