The Canadian Centre for Cyber Security warned that MISP 2.5.45 and earlier are affected by one or more vulnerabilities and urged administrators to apply vendor updates. MISP subsequently released version 2.5.46, delivering security hardening that includes fixes for sharing-group authorization, outbound-request validation, authentication and session handling, CSRF/XSS protections, logging, throttling, and file-deletion safeguards.
A corrected sharing-group validation path now explicitly rejects empty sharing_group_id values and verifies that users may use a submitted group, preventing a fail-open condition in which a missing or falsy ID could return the user's full authorized sharing-group list. The release also adds a shared URL egress validator and strengthens the HTTP client to mitigate SSRF exposure through destination restrictions, redirect controls, response-size limits, and TLS peer verification enabled by default; organizations operating MISP should upgrade to 2.5.46 and review vendor guidance.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
MISP released version 2.5.46 with security hardening including outbound-request validation and SSRF protections, stronger authentication, authorization, CSRF and XSS defenses, and sharing-group authorization improvements. The release also included performance improvements, data updates, and usability fixes; administrators were recommended to update.
The Canadian Centre for Cyber Security published advisory AV26-901 concerning vulnerabilities affecting MISP 2.5.45 and earlier. It advised administrators and users to review vendor information and apply necessary updates when available.
MISP versions 2.5.45 and earlier were reported as affected by one or more vulnerabilities as of September 4, 2026. The available advisory information did not specify CVEs, severity, exploitation status, or a fixed version.
Italy's ACN reported that MISP security updates remediate two vulnerabilities affecting versions before 2.5.46. One is rated high severity and could allow a malicious user to bypass security restrictions on affected systems.
MISP introduced a centralized SharingGroup::canUse() authorization check that rejects empty sharing-group IDs and validates that the submitted ID matches a sharing group authorized for the user. Controllers were updated to consistently validate supplied sharing-group IDs, preventing the prior fail-open behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcemisp-project.org
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.