Arbitrary Code Execution Vulnerability in MISP by Risk Based Security
CVE-2026-94383

8.6HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94383?

A vulnerability in the MISP blocklist workflow module allows an attacker with site-administrator privileges to exploit insufficient validation of user-supplied blocklist filename parameters. The vulnerability occurs due to a lack of proper file extension validation and inadequate sanitization, leading to arbitrary code execution if the server is configured to execute scripts from the MISP export directory. This can result in complete compromise of the MISP server’s confidentiality, integrity, and availability, giving the attacker control over the web server process.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
.