Cross-Site Request Forgery Vulnerability in MISP by MISP Project
CVE-2026-85546

8.6HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85546?

MISP is affected by a cross-site request forgery vulnerability that allows unauthorized state-changing operations on sharing group memberships. Specifically, actions involving adding or removing organizations and servers can be executed via GET requests due to a lack of proper HTTP method enforcement. An attacker could exploit this vulnerability by crafting a malicious URL, potentially compromising the integrity of information sharing among authenticated users. The recent patch addresses this vulnerability by ensuring that specified actions require POST requests, thereby protecting against unauthorized modifications and reinforcing overall security.

Affected Version(s)

misp 0 <= 2.4.54

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
Scottish Government - National Cyber Team
Peter James
.