MISP是MISP组织开源的一套开源的软件解决方案。该产品用于收集、存储、分发、共享网络安全指标,并具有威胁网络安全事件分析和恶意软件分析等功能。 MISP 2.5.41及之前版本存在软件供应链问题漏洞,该漏洞源于允许通过身份验证的站点管理员将Kafka_rdkafka_config设置设置为任意文件系统路径,进而解析引用的INI文件并将选项传递给rdkafka,攻击者控制的配置文件可利用plugin.library.paths等选项加载外部库,从而导致以MISP进程权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56424 | Broken access control in MISP core allows cross-organization unauthorized modification or | |
| CVE-2026-56446 | Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP | |
| CVE-2026-56425 | MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, | |
| CVE-2026-56423 | MISP Core: Broken access control allows instance-wide unauthorized deletion of event repor | |
| CVE-2026-56422 | MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields |
No comments yet