Remote Code Execution Vulnerability in MISP by Affected Redis Configuration
CVE-2026-106513

6.9MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106513?

The Malware Information Sharing Platform (MISP) contains a vulnerability that exposes sensitive Redis host configurations through its web interface and API to users with site-admin privileges. This vulnerability arises from insufficient validation of Redis job payloads by background job workers. If an attacker successfully hijacks a site-admin session, they can manipulate the Redis settings to connect to a malicious Redis server. This allows them to inject harmful job payloads that the workers may execute with the privileges of the site-admin. Furthermore, the attacker can modify the download_attachments_on_load setting, potentially enabling client-side attacks. Since the vulnerability requires elevated privileges and a prior session compromise, it emphasizes the necessity for strong session management and validation mechanisms.

Affected Version(s)

MISP 0 <= 2.5.48

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Logan Homolka
CERT.pl
iglocska
Claude Opus 4.8
CCB
Alexandre Dulaunoy
.