Description
MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CSRF validation (both token and field-hash checks) for those endpoints. Because these endpoints accept POST requests and modify per-user application state (theme selection, default homepage URL, and event index column visibility), an attacker who can induce a logged-in MISP user to load a malicious page (e.g., via a crafted link, embedded image, or auto-submitting form) can forge requests that alter the victim's settings without their knowledge or consent. The most impactful action is setHomePage, which allows an attacker to redirect the victim's default landing page to an arbitrary attacker-controlled URL, potentially facilitating phishing or further social engineering. The setTheme action can alter the user's visual theme, and eventIndexColumnToggle can change which columns are displayed in the event index view. No authentication bypass is involved; the victim must already be authenticated to MISP. The vulnerability was reported by the Scottish Government National Cyber Team.

Version affected: ≤2.5.45
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site request forgery that allows a logged-­in user’s settings to be changed without permission
Action: Immediate Patch
AI Analysis

Impact

The UserSettingsController in MISP was configured to skip all CSRF checks for the setTheme, setHomePage, and eventIndexColumnToggle actions. Because these endpoints accept POST requests that alter per‑user configuration, a malicious site can coerce an authenticated victim to send forged requests that change the victim’s theme, default home page, or event index column visibility. The most dangerous effect is setHomePage, which can redirect the user to an attacker‑controlled URL, enabling phishing or social‑engineering attacks. No authentication bypass is required; the user must already be logged in.

Affected Systems

Versions of MISP up to and including 2.5.45. The vulnerability was specifically noted for the MISP:MISP product line and is not limited to any particular deployment configuration.

Risk and Exploitability

The CVSS score of 5.1 indicates medium severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog. Attackers need to get a logged‑in user to load a malicious page that sends a POST request to one of the vulnerable endpoints. Because the actions were removed from CSRF validation, the forged request succeeds when the victim’s browser sends the request, but legitimate same‑origin requests continue to work under the new CSRF header‑only rule after applying the official fix.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Remediation

Vendor Solution

The fix removes the three affected actions from the Security component's unlockedActions list (which had disabled all CSRF checks) and instead registers them under a header-only CSRF token validation mechanism (_csrfTokenHeaderOnly). This requires the X-CSRF-Token header to be present and valid on each request while still permitting the AJAX-style calls that lack traditional form fields. Client-side JavaScript and view templates are updated to include the X-CSRF-Token header (sourced from window.csrfToken) in all AJAX and fetch calls to these endpoints, ensuring legitimate same-origin requests continue to function while cross-origin forged requests are rejected.


OpenCVE Recommended Actions

  • Apply the official update that removes the affected actions from the Security component’s unlockedActions list and registers validation mechanism (_csrfTokenHeaderOnly).
  • Verify that the MISP application generates an X-CSRF-Token header and that client‑side JavaScript includes this header (all AJAX and fetch calls to the setTheme, setHomePage, and eventIndexColumnToggle endpoints).
  • If the application cannot be patched immediately, consider disabling these endpoints or limiting their use to trusted users to reduce the attack surface until the repair can be applied.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Mon, 14 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CSRF validation (both token and field-hash checks) for those endpoints. Because these endpoints accept POST requests and modify per-user application state (theme selection, default homepage URL, and event index column visibility), an attacker who can induce a logged-in MISP user to load a malicious page (e.g., via a crafted link, embedded image, or auto-submitting form) can forge requests that alter the victim's settings without their knowledge or consent. The most impactful action is setHomePage, which allows an attacker to redirect the victim's default landing page to an arbitrary attacker-controlled URL, potentially facilitating phishing or further social engineering. The setTheme action can alter the user's visual theme, and eventIndexColumnToggle can change which columns are displayed in the event index view. No authentication bypass is involved; the victim must already be authenticated to MISP. The vulnerability was reported by the Scottish Government National Cyber Team. Version affected: ≤2.5.45
Title MISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, and eventIndexColumnToggle Endpoints
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-14T10:28:09.993Z

Reserved: 2026-09-14T09:12:01.736Z

Link: CVE-2026-90893

cve-icon Vulnrichment

Updated: 2026-09-14T10:26:46.809Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:05.930

Modified: 2026-09-16T13:42:47.907

Link: CVE-2026-90893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)