Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106513— MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration Change

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP(恶意软件信息共享平台)通过其 Web 用户界面和 API,向站点管理员用户暴露了关键的基础设施设置,特别是核心应用程序、ZeroMQ 插件以及 SimpleBackgroundJobs 插件所使用的 Redis 主机地址。后台作业 worker 在接收原始 Redis 作业负载时,未进行额外的验证即予以信任。 攻击者若通过存储型跨站脚本(Stored XSS)等漏洞获取被劫持的站点管理员会话,即可修改 Redis 主机设置,使其指向由攻击者控制的 Redis 服务器,随后重启作业 worker 进程。一旦

CVSS 6.9 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP ≤ 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration Change
Source: CVE Program / CVE List V5
Vulnerability Description
MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the download_attachments_on_load setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp_\(malware_information_sharing_platform\):*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-106513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106513

请登录查看更多情报信息。

Other References for CVE-2026-106513 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106513

No comments yet


Leave a comment