PT-2026-96717 · Misp+1 · Misp+1

·

CVE-2026-95658

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description The WorkflowsController exposes the moduleStatelessExecution action within the Security component's unlockedActions list. In the CakePHP framework, including an action in unlockedActions disables field hash validation and Cross-Site Request Forgery (CSRF) token checks. Since moduleStatelessExecution triggers a workflow module's exec() function using input and parameters provided by the caller, an attacker can craft a cross-site form post or cross-origin request. If an authenticated site administrator submits this request, it triggers the action on the MISP instance, allowing the attacker to execute any workflow module, including those that modify blocklist and warninglist entries, with arbitrary parameters.
Recommendations Update to version 2.5.47.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95658

Affected Products

Cakephp
Misp