Stored XSS in MISP Overmind Theme's Dashboard by Vendor
CVE-2026-93296

8.5HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-93296?

MISP's Overmind theme is vulnerable to a stored cross-site scripting (XSS) exploit within its statistics views. Specifically, the event General card and server/feed preview card dynamically generate donut chart legend labels without proper HTML encoding. This oversight allows authenticated users with sufficient permissions to create or modify MISP object names to inject malicious markup. When a victim views the Overmind dashboard, the embedded script runs in their browser context, potentially leading to session hijacking and unauthorized actions. The attack requires low-level authenticated access and victim interaction with the affected dashboard components.

Affected Version(s)

misp < 2.5.47

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 4.8
.