PT-2026-107118 · Misp · Misp

·

CVE-2026-106513

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

6.9

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description Critical infrastructure settings, specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin, are exposed through the web UI and API to site-admin users. Because background job workers trust raw Redis job payloads without additional validation, an attacker with a hijacked site-admin session can redirect these settings to an attacker-controlled Redis server and restart the workers. This allows the injection of malicious job payloads, leading to arbitrary command execution as the worker account and potential data exfiltration. Furthermore, the download attachments on load setting, which manages inline attachment rendering, is modifiable via the same interface, potentially facilitating client-side attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106513

Affected Products

Misp