Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-94383: MISP allows admin to run arbitrary scripts via blocklist

CVE-2026-94383 · published 19 days ago
Summary

The blocklist feature in MISP versions before 2.5.47 lets a site administrator name a file with any extension, which is then saved in the web server’s export folder. If the web server is set to run files from that folder, the saved file can be executed, giving the attacker the same rights as the web server. To protect your system, update MISP to the latest version or restrict script execution in the export directory.

What to do
  • Update misp misp to version 2.5.47 or later.
Affected software
VendorProductAffected versions
misp misp < 2.5.47
Original advisory text
MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File Extension
The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a filename with an arbitrary extension that would be placed in the MISP export directory. If the underlying web server is configured to interpret and execute scripts from that directory, the resulting file could be invoked, leading to arbitrary code execution in the context of the web server process.

The vulnerability requires the attacker to hold site-administrator privileges within MISP, as the blocklist workflow module is restricted to that role. No additional user interaction is required beyond triggering the workflow action with a crafted filename parameter. The impact is full compromise of the MISP server's confidentiality, integrity, and availability, as arbitrary script execution grants the attacker the same privileges as the web server user.

Version affected: <2.5.47
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
CWE-434Unrestricted File Upload
Timeline
Published21 Sep 2026
Updated7 Oct 2026
First seen21 Sep 2026
Sources
CVE-2026-94383 · MITRE
Track software like this
Free during beta