VYPR
Vypr IntelligenceAI-generatedSep 30, 2026· 6 CVEs

MISP: Six Vulnerabilities Including XSS and Privilege Escalation Disclosed Together

Six vulnerabilities, four rated High, were disclosed for MISP on September 30, 2026, stemming from input validation flaws across multiple features.

Key findings

  • Six vulnerabilities in MISP disclosed on Sept 30, 2026, four rated High.
  • Flaws include stored XSS, privilege escalation, and mass assignment vulnerabilities.
  • Vulnerabilities stem from improper input validation and lack of server-side sanitization.
  • Galaxy, event graph, tag collection, and delegation features are affected.
  • Users urged to update MISP to patched versions immediately.

On September 30, 2026, a batch of six vulnerabilities was disclosed for MISP (Malware Information Sharing Platform), a threat intelligence sharing platform. The vulnerabilities, disclosed within a five-hour window, range in severity from Medium to High, with four rated as High. These flaws primarily stem from improper input validation and lack of server-side sanitization across various features, including galaxy management, event graphing, tag collections, and event delegation. The most critical issues could allow for privilege escalation and stored cross-site scripting (XSS) attacks.

Several of the vulnerabilities are related to the handling of user-provided data within MISP's galaxy feature. CVE-2026-103389, a stored XSS vulnerability, arises because the 'icon' field of a galaxy object is persisted without server-side validation. This stored value is then directly embedded into HTML markup, potentially executing malicious scripts when rendered. Similarly, CVE-2026-103388, also a stored XSS vulnerability, exploits the galaxy's 'source' field. While MISP attempts to render this as a hyperlink if it passes URL validation, it incorrectly accepts 'javascript:' URIs, allowing authenticated users to inject executable scripts.

Further impacting data integrity and security are vulnerabilities related to event and tag management. CVE-2026-103239 details a privilege escalation flaw in tag collection creation and editing. The affected functionality accepts the full HTTP request payload, leading to the unintended saving of associated model data beyond the intended tag collection record. CVE-2026-103237, an improper input validation vulnerability in the ORM save path, affects multiple endpoints including attribute add/edit, event edit, and more. This flaw allows for the persistence of unsanitized data across various critical operations.

Two high-severity vulnerabilities focus on broader system compromise. CVE-2026-103235, a mass assignment vulnerability in the event delegation feature, allows a user with delegation permissions to persist entire submitted records, including fields not intended for modification, by exploiting the application's authorization checks. Finally, CVE-2026-103321, another stored XSS vulnerability, affects the event graph preview feature. The 'event graph preview image' field is stored without validation and later concatenated into an HTML <img> tag's src attribute, enabling the injection of malicious scripts.

The disclosure of these six vulnerabilities highlights a pattern of insufficient server-side validation in critical MISP components. Users are advised to update to patched versions as soon as possible. The specific versions containing fixes were not detailed in the provided information, but the prompt indicates a coordinated disclosure event on September 30, 2026. Addressing these flaws is crucial to prevent unauthorized script execution, privilege escalation, and potential data corruption within MISP instances.

The batch of vulnerabilities disclosed on September 30, 2026, for MISP includes:

These vulnerabilities were all disclosed on the same day, indicating a coordinated disclosure event. The severity ranges from Medium to High, with four of the six vulnerabilities rated as High. The common theme across these flaws is the lack of robust server-side validation and sanitization of user-supplied input in various modules of the MISP platform.

The impact of these vulnerabilities includes the potential for stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by other users. Privilege escalation is also a significant risk, enabling lower-privileged users to gain higher-level access within the MISP instance. Improper input validation and mass assignment vulnerabilities can lead to data corruption, unauthorized modifications, and a broader compromise of the system's integrity.

Users of MISP are strongly urged to apply any available patches or updates provided by the vendor to mitigate these risks. Given the coordinated nature of the disclosure, it is likely that a single update addresses all or most of these issues. It is recommended to consult the official MISP security advisories for specific version information and remediation steps.

This batch of vulnerabilities underscores the importance of continuous security auditing and timely patching for platforms like MISP, which handle sensitive threat intelligence data. Users should remain vigilant for further security updates and best practices recommended by the MISP community. The concentration of high-severity flaws in a single disclosure event highlights a critical window of risk that requires immediate attention from administrators.

AI-written article. Grounded in 6 CVE records listed below.