Cross-Site Request Forgery Vulnerability in MISP by MISP Project
CVE-2026-85546
8.6HIGH
What is CVE-2026-85546?
MISP is affected by a cross-site request forgery vulnerability that allows unauthorized state-changing operations on sharing group memberships. Specifically, actions involving adding or removing organizations and servers can be executed via GET requests due to a lack of proper HTTP method enforcement. An attacker could exploit this vulnerability by crafting a malicious URL, potentially compromising the integrity of information sharing among authenticated users. The recent patch addresses this vulnerability by ensuring that specified actions require POST requests, thereby protecting against unauthorized modifications and reinforcing overall security.
Affected Version(s)
misp 0 <= 2.4.54
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andras Iklody
Scottish Government - National Cyber Team
Peter James
