PT-2026-85050 · Misp · Misp

·

CVE-2026-85221

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description An improper TLS certificate validation issue exists in the CurlClient component. The CurlClient::$verifyPeer property was not explicitly initialized, defaulting to null, which effectively disabled TLS peer verification during cURL operations unless explicitly enabled by the calling code. This allows HTTPS connections to accept certificates not issued by a trusted certificate authority. A man-in-the-middle attack could be performed by an attacker capable of intercepting network traffic between a MISP instance and a remote HTTPS service to impersonate the endpoint. This could lead to the observation of sensitive information, such as authentication material and threat intelligence, or the modification of responses returned to the MISP instance.
Recommendations Apply the available patch to enable TLS peer verification by default and correct self-signed certificate handling in the SyncTool component.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85221

Affected Products

Misp