PT-2026-96786 · Misp · Misp

·

CVE-2026-95806

·

Published

2026-09-22

·

Updated

2026-09-24

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description MISP registers the PHP phar stream wrapper in its web and console entry points. This wrapper causes PHP to treat phar archives as directories, leading to two security risks: any filesystem operation on a path influenced by a caller that resolves to a phar archive triggers an implicit unserialize() call, creating a deserialization sink, and a relocated application root may access executable code within an uploaded phar file, allowing arbitrary code execution as the web user. The wrapper serves no legitimate purpose within the MISP runtime, the CakePHP framework, or its loaded libraries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95806

Affected Products

Misp