PT-2026-48996 · Misp · Misp

·

CVE-2026-54394

·

Published

2026-06-12

·

Updated

2026-06-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A path traversal issue exists in the getOrgLogo() function of the OrganisationsController. The software constructs file paths for organization logos using fields controlled by the organization, such as id, name, and uuid, without verifying that the resulting path stays within the intended APP/files/img/orgs/ directory. An attacker who can modify an organization field, such as the organization name, can use path traversal sequences to retrieve arbitrary readable .png or .svg files from locations outside the designated logo directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54394

Affected Products

Misp