URL Validation Flaw in MISP Dashboard Button Widget Exposed by Vendor
CVE-2026-10856

5.1MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-10856?

The MISP dashboard button widget contained a URL validation flaw that allowed crafted URLs to bypass security measures, permitting attackers to redirect users to malicious external sites. The widget incorrectly accepted URLs starting with certain patterns, such as a backslash, posing serious risks for phishing and credential theft. By exploiting this flaw, attackers could create deceptive dashboard buttons that appeared to direct users within the application while actually linking them to attacker-controlled domains. Security measures have since been implemented to mitigate this issue by enforcing strict validation rules on URLs.

Affected Version(s)

misp 0 <= 2.5.38

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
Jeroen Pinoy
.