MISP 在 CustomAuth 认证(一种自定义配置)流程中存在一个会话固定(Session Fixation)漏洞。当用户通过 CustomAuth 成功认证后,MISP 会将已认证的用户身份写入现有的会话中,但未先轮换会话标识符(Session ID)。 后果: 如果攻击者能够诱导受害者在认证前使用攻击者已知的会话标识符,那么该会话标识符在受害者成功认证后依然有效。攻击者随后可以复用这个被固定的会话标识符,从而访问受害者的已认证 MISP 会话,并可能获得与受害者账户相关的权限。 根本原因: 该问题的原因是
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85216 | 9.5 CRITICAL | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-85236 | 8.8 HIGH | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85237 | 8.6 HIGH | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass |
| CVE-2026-85221 | 7.6 HIGH | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attack |
| CVE-2026-85239 | 7.1 HIGH | MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service |
| CVE-2026-85227 | 6.1 MEDIUM | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAtta |
| CVE-2026-85226 | 5.3 MEDIUM | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Co |
| CVE-2026-85230 | 5.3 MEDIUM | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
No comments yet