Cross-Site Request Forgery Vulnerability in CTI-Transmute by MISP
CVE-2026-69082

8.8HIGH

Key Information:

Vendor

Misp

Vendor
CVE Published:
3 August 2026

What is CVE-2026-69082?

CTI-Transmute has a vulnerability in its administrative user deletion feature, allowing an unauthenticated remote attacker to exploit the /account/delete/ endpoint via crafted links. This flaw enables an attacker to delete user accounts without administrator consent, as it relies on the active session of an authenticated administrator. The attacker can trick the administrator into visiting a malicious site, thereby executing an unintended account deletion. This can result in unauthorized changes to application states and potential denial of access for users. The vulnerability was mitigated by restricting the deletion action to HTTP POST requests and requiring a CSRF token in the form.

Affected Version(s)

cti-transmute 0 <= 1.4.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Christian Studer
.