File Existence Disclosure in MISP by MISP Project
CVE-2026-95703
5.1MEDIUM
What is CVE-2026-95703?
In MISP, the OrganisationsController::__uploadLogo method improperly handles the tmp_name parameter, allowing authenticated site-admin users to supply arbitrary server file paths. This leads to a situation where the application can confirm if specific paths exist on the server and determine the type of image files based on the responses. This behavior effectively creates a validation oracle that can leak information about the server's filesystem and the types of images stored therein.
Affected Version(s)
MISP 0 < 2.5.47
