Path Traversal Vulnerability in MISP Affected by User-Controlled Input
CVE-2026-95698
5.3MEDIUM
What is CVE-2026-95698?
The findOrgImage method in MISP's OrgImgHelper is vulnerable due to inadequate validation of user-supplied organization identifiers during filesystem path construction. An attacker can exploit this issue by utilizing directory traversal sequences in the organization name, which may lead to the disclosure of sensitive files outside the intended directory. The vulnerability allows authenticated users to read arbitrary files with .png or .svg extensions, exposing potential data leaks. It's imperative for organizations using MISP to apply the necessary security updates to mitigate this risk.
Affected Version(s)
MISP 0 < 2.5.47
