Arbitrary Code Execution Vulnerability in MISP by Risk Based Security
CVE-2026-94383
8.6HIGH
What is CVE-2026-94383?
A vulnerability in the MISP blocklist workflow module allows an attacker with site-administrator privileges to exploit insufficient validation of user-supplied blocklist filename parameters. The vulnerability occurs due to a lack of proper file extension validation and inadequate sanitization, leading to arbitrary code execution if the server is configured to execute scripts from the MISP export directory. This can result in complete compromise of the MISP server’s confidentiality, integrity, and availability, giving the attacker control over the web server process.
Affected Version(s)
MISP 0 < 2.5.47
