Information Disclosure Vulnerability in MISP by the Vendor MISP
CVE-2026-95693

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95693?

An information disclosure vulnerability exists in MISP due to improper handling of user-supplied file paths in the EventReport::uploadPicture method. An authenticated user with requisite permissions can supply arbitrary filesystem paths as the temporary name for file uploads without the application first validating if the uploaded file is genuine. This could allow an attacker to probe the filesystem of the MISP server, potentially revealing sensitive file information such as locations of configuration files, private keys, and other artifacts. The vulnerability's exploitation is limited to revealing the presence and file type of files but does not grant access to read file contents, write files or execute code, which may help in planning subsequent attacks.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 4.8
.