File Existence Disclosure in MISP by MISP Project
CVE-2026-95703

5.1MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95703?

In MISP, the OrganisationsController::__uploadLogo method improperly handles the tmp_name parameter, allowing authenticated site-admin users to supply arbitrary server file paths. This leads to a situation where the application can confirm if specific paths exist on the server and determine the type of image files based on the responses. This behavior effectively creates a validation oracle that can leak information about the server's filesystem and the types of images stored therein.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iglocska
Claude Opus 4.8
.