Cross-Site Scripting Vulnerability in MISP TAXII Object Viewer
CVE-2026-104906

6.2MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104906?

The MISP application is exposed to a cross-site scripting (XSS) vulnerability found in the TAXII object viewer. This issue arises when remote TAXII objects are displayed, as the JSON content of string properties is rendered directly into an HTML pre block without proper HTML encoding. An attacker can exploit this by publishing a malicious TAXII object that the victim's MISP instance subscribes to, allowing them to execute arbitrary JavaScript within the context of the victim's MISP session. This vulnerability requires the victim to be an authenticated MISP user with access to the TAXII object viewer and to interact with the crafted TAXII object, resulting in the potential theft of session tokens, API keys, or other sensitive data available in the MISP user interface, as well as the ability to maneuver actions on behalf of the authenticated user.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 5.5 (1M context)
.