SQL Injection Vulnerability in MISP Threat Intelligence Platform
CVE-2026-44381

9.3CRITICAL

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44381?

MISP, an open-source threat intelligence platform, was found to have a SQL injection vulnerability in its user-controlled ordering parameters prior to version 2.5.37. This flaw occurs in the event and shadow attribute listing endpoints, where inadequate validation of ordering parameters allows an attacker to manipulate SQL queries. By exploiting this vulnerability, unauthorized users could potentially access or modify sensitive information within the database, depending on their database permissions and the specific query context used. Users are strongly advised to upgrade to version 2.5.37 to mitigate this issue.

Affected Version(s)

MISP < 2.5.37

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.