PT-2026-107118 · Misp · Misp
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
Critical infrastructure settings, specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin, are exposed through the web UI and API to site-admin users. Because background job workers trust raw Redis job payloads without additional validation, an attacker with a hijacked site-admin session can redirect these settings to an attacker-controlled Redis server and restart the workers. This allows the injection of malicious job payloads, leading to arbitrary command execution as the worker account and potential data exfiltration. Furthermore, the
download attachments on load setting, which manages inline attachment rendering, is modifiable via the same interface, potentially facilitating client-side attacks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp