Information Disclosure Vulnerability in MISP by the Vendor MISP
CVE-2026-95693
What is CVE-2026-95693?
An information disclosure vulnerability exists in MISP due to improper handling of user-supplied file paths in the EventReport::uploadPicture method. An authenticated user with requisite permissions can supply arbitrary filesystem paths as the temporary name for file uploads without the application first validating if the uploaded file is genuine. This could allow an attacker to probe the filesystem of the MISP server, potentially revealing sensitive file information such as locations of configuration files, private keys, and other artifacts. The vulnerability's exploitation is limited to revealing the presence and file type of files but does not grant access to read file contents, write files or execute code, which may help in planning subsequent attacks.
Affected Version(s)
MISP 0 < 2.5.47
