The Canadian Centre for Cyber Security warned that MISP CTI-Transmute versions <= 1.4.0 are affected by multiple vulnerabilities, including CVE-2026-69082 and **CVE-2026-69079. One flaw allows **cross-site request forgery (CSRF)** against the administrative user-deletion endpoint because /account/delete/<id>accepted HTTPGET` requests for a state-changing action, letting an attacker trick a logged-in administrator into deleting a chosen user account. The issue could cause unauthorized state changes, denial of access for affected users, and potential disruption if administrator accounts are targeted.
A second high-severity flaw allows unauthenticated denial of service through the /activity_timeline endpoint, where an unbounded days parameter could be abused to force excessive database, CPU, and memory consumption and degrade site availability. The advisory also referenced remediation for blocking file and network fetches during evaluation PDF rendering, alongside fixes that cap the timeline range and require POST plus CSRF protection for user deletion. Administrators were urged to review the linked fixes and apply updates as they become available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-775 stating that, as of August 3, 2026, MISP was affected by vulnerabilities in the cti-transmute component up to and including version 1.4.0. The notice directed administrators to review linked fixes, including capping the activity-timeline range and requiring POST for user deletion.
A CVE entry was newly received for CVE-2026-69082, a cross-site request forgery issue in CTI-Transmute's administrative user deletion endpoint affecting versions up to and including 1.4.0. The flaw let an unauthenticated attacker trick an authenticated administrator into deleting user accounts via a GET request.
CVE-2026-69079 was published for an unauthenticated denial-of-service vulnerability in CTI-Transmute's /activity_timeline endpoint affecting versions up to and including 1.4.0. The flaw allowed attackers to supply an unbounded days parameter and exhaust database, CPU, and memory resources.
A GitHub commit in MISP's cti-transmute project changed the /account/delete/<int:id> route to accept only POST requests and updated the admin user detail page to submit deletions through a form. The change added a CSRF token to the deletion workflow, addressing the unsafe GET-based user deletion behavior.
A GitHub commit in MISP's cti-transmute project fixed the unauthenticated /activity_timeline endpoint by clamping the days parameter to between 1 and 1,095 days. The change addressed the unbounded input that could tie up the server or trigger a 500 error.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.