[NEU] [hoch] MISP: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen, beliebigen Code auszuführen und Benutzer auf bösartige URLs umzuleiten.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3370
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-90893 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-90895 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-90955 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-90957 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-90961 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-91851 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-91825 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-91846 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-91851: Affected versions of MISP incorrectly filter dashboard templates that are restricted to a spec…nvd
- unknownCVE-2026-91846: Affected versions of MISP allow a collection element to be created from a bare UUID without co…nvd
- unknownCVE-2026-91825: Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit…nvd
- unknownCVE-2026-90961: The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vu…nvd
- unknownCVE-2026-90957: Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandb…nvd
- unknownCVE-2026-90955: Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the…nvd
- unknownCVE-2026-90895: Affected versions of MISP’s interactive CLI shell implement access control independently from …nvd
- unknownCVE-2026-90893: MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController.…nvd
Recent advisories for MISP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-92003: Affected versions of MISP do not consistently apply the existing authentication-failure loggin…nvd · 2026-09-15
- unknownCVE-2026-92002: Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. T…nvd · 2026-09-15
- unknownCVE-2026-91859: Affected versions of MISP can record incorrect access-log data for requests that terminate in …nvd · 2026-09-15
- unknownCVE-2026-91857: Affected versions of MISP expose several state-changing controller actions without restricting…nvd · 2026-09-15
- unknownCVE-2026-91851: Affected versions of MISP incorrectly filter dashboard templates that are restricted to a spec…nvd · 2026-09-15
- unknownCVE-2026-91846: Affected versions of MISP allow a collection element to be created from a bare UUID without co…nvd · 2026-09-15
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15