Unauthorized Data Modification in MISP by Attacker-Controlled Pages
CVE-2026-94404
7.1HIGH
What is CVE-2026-94404?
MISP is exposed to a cross-site request forgery (CSRF) vulnerability that permits attackers to manipulate threat-intelligence data through an authenticated user's browser session without their consent. If an authenticated user unknowingly visits a malicious webpage, the attacker can send unauthorized requests to MISP. This may result in changes to essential data elements, compromising the integrity and trustworthiness of threat intelligence. Such modifications can create incorrect indicators, alter classifications, or modify sharing settings, ultimately impacting the reliability of the intelligence stored within MISP.
Affected Version(s)
MISP 0 < 2.5.47
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jeroen Pinoy
iglocska
Claude Opus 5 (1M context)
