Cross-Site Request Forgery Vulnerability in MISP by GnuPG
CVE-2026-95658

6.9MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95658?

The MISP application exposes a critical vulnerability through the moduleStatelessExecution action within the Security component. When this action is listed in unlockedActions of CakePHP, it effectively bypasses important safeguards such as CSRF token verification and field hash validation. Attackers can exploit this weakness by crafting cross-site requests that, when executed by an authenticated administrator, could lead to unauthorized actions within the MISP instance. This includes manipulating security-related data such as blocklist and warninglist entries, representing a significant integrity risk to the application. The vulnerability was identified during an internal security review and is addressed in MISP version 2.5.47.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iglocska
Claude Opus 5 (1M context)
.