PT-2026-85456 · Misp · Misp

·

CVE-2026-85547

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

6.2

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A cross-site request forgery (CSRF) issue occurs because the system disables form-security and CSRF protections if a request is identified as REST traffic. This detection can be manipulated by an attacker using the HTTP Accept header (e.g., Accept: application/json), which can be sent from a cross-origin page without a CORS preflight. Consequently, the system may treat a request from a malicious website as REST traffic and bypass security validations while using the victim's authenticated browser session. An attacker could trick an authenticated user into visiting a malicious page to execute unauthorized state-changing requests to susceptible endpoints, potentially leading to the unauthorized modification, creation, publication, or removal of data. The issue stems from the isRest() function granting security exemptions based on request type rather than the authentication mechanism.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85547

Affected Products

Misp