Stored XSS in MISP Overmind Theme's Dashboard by Vendor
CVE-2026-93296
8.5HIGH
What is CVE-2026-93296?
MISP's Overmind theme is vulnerable to a stored cross-site scripting (XSS) exploit within its statistics views. Specifically, the event General card and server/feed preview card dynamically generate donut chart legend labels without proper HTML encoding. This oversight allows authenticated users with sufficient permissions to create or modify MISP object names to inject malicious markup. When a victim views the Overmind dashboard, the embedded script runs in their browser context, potentially leading to session hijacking and unauthorized actions. The attack requires low-level authenticated access and victim interaction with the affected dashboard components.
Affected Version(s)
misp < 2.5.47
