MISP 受影响版本中, 对电子邮件地址可见性的执行不一致。 该查询始终会获取 字段,而信息脱敏(隐藏处理)仅在非 REST 的渲染分支中执行。结果是,同一位已认证用户在常规 HTML 界面中看到的是经过脱敏的数据,但通过请求 REST/JSON 表示时,却能够绕过预期的权限检查,获取到模板所有者的电子邮件地址。 修复方案将权限判断逻辑迁移至集中式的 授权辅助函数。现在,只有当请求者是站点管理员,或实例显式启用了 配置时,才会获取电子邮件地址。该辅助函数也被其他仪表盘组件复用,以确保电子邮件披露策略的一致性。 受影
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86452 | 8.7 HIGH | MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Floodi |
| CVE-2026-86347 | 7.1 HIGH | MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion |
| CVE-2026-86408 | 7.1 HIGH | MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected E |
| CVE-2026-86419 | 7.0 HIGH | MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed R |
| CVE-2026-86342 | 5.3 MEDIUM | MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Inform |
| CVE-2026-86451 | 5.3 MEDIUM | MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects |
| CVE-2026-86351 | 5.1 MEDIUM | MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL |
| CVE-2026-86440 | 5.1 MEDIUM | MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs |
| CVE-2026-86418 | 2.3 LOW | MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Us |
| CVE-2026-86441 | 2.3 LOW | MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidd |
No comments yet