Shell Command Injection in Cisco FireSIGHT Manager API via MISP Modules
CVE-2026-97863
What is CVE-2026-97863?
The cisco_firesight_manager_ACL_rule_export module within misp-modules is susceptible to a shell command injection vulnerability. This occurs when configuration variables, such as IP addresses and credentials, are improperly handled in single-quoted shell strings, allowing an attacker to inject malicious shell commands. If a security analyst executes the unmodified generated script, they could potentially unwittingly execute unauthorized commands with their own privileges, leading to severe security risks such as credential exposure and modification of ACL rules. Additionally, a secondary flaw involving the handling of the 'config' variable may cause a denial of service due to NameErrors when certain request payloads are missing necessary keys. This vulnerability necessitates that the attacker possesses privilege to submit specific MISP events or attributes but does not require authentication bypass.
Affected Version(s)
misp-modules 0 <= 3.0.10
