MISP: 20 Vulnerabilities Including Critical Auth Flaws and XSS Disclosed Together
Key findings • 20 vulnerabilities disclosed for MISP between Sept 30 and Oct 2, 2026, including Critical and High severity flaws. • Flaws include critical authentication bypasses, privilege e…

Key findings
- 20 vulnerabilities disclosed for MISP between Sept 30 and Oct 2, 2026, including Critical and High severity flaws.
- Flaws include critical authentication bypasses, privilege escalation, mass assignment, and numerous XSS vulnerabilities.
- Multiple CVEs stem from improper input validation and insufficient server-side sanitization across various MISP features.
- Access control and authorization issues affect attribute search, correlation, event handling, and tag management.
- Users are urged to update MISP instances immediately to patched versions to mitigate these risks.
On October 2, 2026, a significant batch of 20 vulnerabilities was disclosed for MISP (Malware Information Sharing Platform), a threat intelligence sharing platform. These vulnerabilities, disclosed between September 30 and October 2, 2026, span a range of severity levels, including critical, high, and medium, and highlight issues with access control, input validation, and cross-site scripting (XSS). The disclosures collectively underscore the importance of robust security practices for users of the MISP platform.
Several vulnerabilities revolve around improper access control and authorization flaws. CVE-2026-104914 (Medium) and CVE-2026-104912 (High) both involve issues with attribute search and correlation handling, where soft-deleted attributes or correlated attributes could be accessed improperly. Similarly, CVE-2026-104910 (Medium) details an authorization bypass in the related events listing, allowing access to metadata without proper validation. Further access control issues are seen in CVE-2026-103858 (Medium), concerning discussion posting, and CVE-2026-103659 (High), which bypasses authorization during event flattening. CVE-2026-103239 (High) represents a privilege escalation vulnerability in tag collection management, where improper handling of request payloads could lead to unintended data writes.
Input validation and sanitization were also significant themes within this batch. CVE-2026-104908 (High) points to improper input validation in the decaying model import functionality, allowing unintended data manipulation. CVE-2026-103237 (High) highlights a broader issue with improper input validation in the ORM save path, affecting numerous endpoints including attribute and event editing, and imports.
Cross-site scripting (XSS) vulnerabilities are prevalent across several CVEs. CVE-2026-104907 (Medium), CVE-2026-104906 (Medium), CVE-2026-104901 (Medium), CVE-2026-104900 (Medium), CVE-2026-103664 (Medium), CVE-2026-103662 (Medium), CVE-2026-103389 (Medium), and CVE-2026-103388 (Medium) all detail various forms of stored or reflected XSS. These vulnerabilities arise from insufficient sanitization of user-supplied data in different components, including attribute previews, TAXII object viewers, ID translators, galaxy icons, and source fields. CVE-2026-103321 (High) specifically details a stored XSS in the event graph preview feature, where unsanitized image data could be rendered in an <img> tag.
Two critical vulnerabilities related to authentication were also disclosed. CVE-2026-103655 (Critical) describes a flaw in the two-factor authentication (TOTP) verification process, allowing valid codes to be accepted more than once within their validity window. CVE-2026-103651 (High) addresses a vulnerability in the one-time password (OTP) authentication flow, permitting the replay of consumed HOTP tokens and the rewinding of the token counter.
Finally, CVE-2026-103235 (High) involves a mass assignment vulnerability in the event delegation feature, where submitted records could include unauthorized fields.
The batch of vulnerabilities was disclosed by multiple sources, with a significant portion appearing on October 1st and 2nd. Related coverage from Vypr Intelligence on September 30, 2026, highlighted six of these vulnerabilities, including XSS and privilege escalation flaws, stemming from improper input validation and lack of server-side sanitization. Users are urged to update their MISP instances to patched versions to mitigate these risks.
This extensive disclosure event serves as a critical reminder for MISP users to promptly apply security updates. The breadth of vulnerabilities, affecting core functionalities like authentication, data handling, and user access, necessitates immediate attention to ensure the integrity and security of threat intelligence shared through the platform. Staying informed about security advisories and maintaining up-to-date instances are crucial for protecting against potential exploitation.