Remote Code Execution Vulnerability in MISP by the MISP Project
CVE-2026-93295
8.7HIGH
What is CVE-2026-93295?
MISP includes a significant vulnerability in its background job dispatch mechanism, permitting remote code execution via unchecked input in job arguments. The vulnerability arises when user-controlled fields from the contact form are incorporated directly into the background job arguments without validation. This allows an attacker to manipulate fields to inject malicious PHP code from a crafted phar:// URI, thereby executing arbitrary commands with the privileges of the web server. Successful exploitation can lead to severe consequences, including data exfiltration and further intrusions within the host system.
Affected Version(s)
misp < 2.5.47 < 2.5.47
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Niels Teusink of Eye Security
iglocska
Claude Opus 5 (1M context)
