SQL Injection Vulnerability in MISP Threat Intelligence Platform
CVE-2026-44381
9.3CRITICAL
What is CVE-2026-44381?
MISP, an open-source threat intelligence platform, was found to have a SQL injection vulnerability in its user-controlled ordering parameters prior to version 2.5.37. This flaw occurs in the event and shadow attribute listing endpoints, where inadequate validation of ordering parameters allows an attacker to manipulate SQL queries. By exploiting this vulnerability, unauthorized users could potentially access or modify sensitive information within the database, depending on their database permissions and the specific query context used. Users are strongly advised to upgrade to version 2.5.37 to mitigate this issue.
Affected Version(s)
MISP < 2.5.37
