Cross-Site Request Forgery Vulnerability in MISP by GnuPG
CVE-2026-95658
What is CVE-2026-95658?
The MISP application exposes a critical vulnerability through the moduleStatelessExecution action within the Security component. When this action is listed in unlockedActions of CakePHP, it effectively bypasses important safeguards such as CSRF token verification and field hash validation. Attackers can exploit this weakness by crafting cross-site requests that, when executed by an authenticated administrator, could lead to unauthorized actions within the MISP instance. This includes manipulating security-related data such as blocklist and warninglist entries, representing a significant integrity risk to the application. The vulnerability was identified during an internal security review and is addressed in MISP version 2.5.47.
Affected Version(s)
MISP 0 < 2.5.47
