PT-2026-96728 · Misp · Misp

·

CVE-2026-95674

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description The queryEnrichment() function in EventsController.php fails to properly validate the module name parameter. When a module name is provided that is not in the list of enabled modules, the system continues processing with default parameters, such as setting the format to 'simplified', instead of rejecting the request. This allows an authenticated user to bypass module availability controls and trigger enrichment or analysis processing through modules not explicitly authorized by the administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95674

Affected Products

Misp