Path Traversal Vulnerability in MISP Affected by User-Controlled Input
CVE-2026-95698

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95698?

The findOrgImage method in MISP's OrgImgHelper is vulnerable due to inadequate validation of user-supplied organization identifiers during filesystem path construction. An attacker can exploit this issue by utilizing directory traversal sequences in the organization name, which may lead to the disclosure of sensitive files outside the intended directory. The vulnerability allows authenticated users to read arbitrary files with .png or .svg extensions, exposing potential data leaks. It's imperative for organizations using MISP to apply the necessary security updates to mitigate this risk.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 4.8
.