PT-2026-38309 · Unknown · Misp-Modules

CVE-2026-44364

·

Published

2026-05-06

·

Updated

2026-06-29

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions MISP modules versions 3.0.7 and earlier
Description A Cross-Site Request Forgery (CSRF) issue in the MISP Modules website allows an attacker to trick an authenticated user into submitting unintended requests to the "/home" endpoint. This occurs because the home blueprint is exempted from CSRF protection, potentially enabling the modification of session query data within the authenticated user's context.
Recommendations Update to a version later than 3.0.7 to enable CSRF protection for the affected blueprint and implement hardened query parsing.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44364
GHSA-J4RH-7JCR-QM69
PYSEC-2026-414

Affected Products

Misp-Modules