MISP deployments running versions earlier than 2.5.48 are affected by multiple security vulnerabilities, including a critical TOTP MFA replay flaw (CVE-2026-103655) and high-severity authorization and mass-assignment issues. A user with perm_tag_editor could inject User or Organisation data through tag-collection saves to create or alter privileged accounts (CVE-2026-103239), while a user with perm_delegate could retarget event delegations to arbitrary events and potentially gain access to another organisation’s threat-intelligence data (CVE-2026-103235). The TOTP flaw permits reuse of an intercepted valid authentication code within its normal validity window, enabling an additional session as the victim.
The update also binds delegation requests to authorized events and prevents nested model aliases or tag-collection save requests from modifying unrelated database rows. Authorities including Italy’s ACN and the Canadian Centre for Cyber Security urged administrators to apply the available MISP update, review audit logs for unauthorized user, organisation, delegation, and role changes, and validate permissions. Separately, MISP’s recent hardening releases addressed a broader set of defects—including XSS, SSRF, local-file-read, access-control, and authenticated remote-code-execution issues—following an external security review; administrators should ensure they are running the latest fixed release, particularly where MFA and delegation are enabled.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published AV26-986 covering MISP vulnerabilities affecting versions before 2.5.48. The advisory highlighted fixes binding delegation requests to authorized events, preventing unintended nested-model save targets and sibling-row writes, and rejecting previously used TOTP codes.
CVE-2026-103655 was published for a critical flaw in MISP versions before 2.5.48 that allowed a valid TOTP code to be reused within its validity window. An attacker who captured a victim's code could establish an additional authenticated session as that user.
CVE-2026-103321 was published for a stored XSS issue in MISP event graph previews. A user able to edit an event graph could store a crafted preview-image value that executes JavaScript when another user opens its preview popover.
MISP released version 2.5.47 after an external security review, confirming, fixing, and retesting 27 vulnerabilities. The update addressed XSS, authorization and CSRF flaws, API-key privilege escalation, MFA and brute-force bypasses, SSRF, local-file reads, path traversal, and authenticated background-job remote code execution.
CVE-2026-103239 documented that tag-collection requests in MISP versions before 2.5.48 could write attacker-supplied sibling User or Organisation model data. An authenticated user with perm_tag_editor could create or modify privileged accounts and potentially escalate to site administrator.
CVE-2026-103235 documented a mass-assignment flaw affecting MISP versions before 2.5.48. A user with perm_delegate could manipulate delegation record identifiers to expose another organisation's events or, if accepted, transfer event ownership.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcemisp-project.org
Open sourcemisp-project.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.