Description
Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation.

CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and DELETE, CakePHP also clears the parsed request body. MISP’s security component then determines whether to perform _validatePost() and _validateCsrf() based on whether request data remains. With a value such as:


_method=GET

the body becomes empty before those checks run, so both protections are skipped. A cross-site form containing only that override can therefore reach actions whose parameters are taken from the URL rather than the request body

Version affected: ≤2.5.45
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: CSRF bypass and form‑validation bypass in MISP
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is rooted in improper input validation (CWE‑20) and cross‑352). An attacker can override the HTTP method used by CakePHP to a non‑write verb such as GET, causing the framework to clear the request body. Because MISP’s security logic checks for performing CSRF and form validation, an empty body causes these protections to be skipped entirely. A crafted form or request that only changes the '_method' field or 'X-HTTP-Method-Override' header can therefore reach actions that rely on URL parameters, enabling an attacker to execute unintended operations without CSRF tokens or form validation.

Affected Systems

Affected versions are MISP 2.5.45 and earlier. The offending code path resides in MISP’s BetterSecurityComponent, which is used by all MISP installations built on CakePHP.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely, and MISP is not listed in the CISA KEV catalogue. The attack vector is a web‑based request or cross‑site form that supplies an '_method' value or 'X-HTTP-Method-Override' header outside the allowed set. Successful exploitation would allow an attacker to bypass CSRF protection and send unauthorized requests to MISP endpoints that accept URL‑based parameters.

Generated by OpenCVE AI on September 17, 2026 at 18:03 UTC.

Remediation

Vendor Solution

The fix introduces a __rejectUnsafeMethodOverride() check in BetterSecurityComponent::startup() that executes before the parent SecurityComponent::startup() computes $hasData. It inspects both the _method POST field and the X-HTTP-Method-Override header (mirroring CakePHP's precedence) and rejects any value that is not a string in the allowed set {POST, PUT, PATCH, DELETE}. Non-string values (e.g., array payloads like _method[]=GET) are also refused. A BadRequestException is thrown and the event is logged, preventing the request from ever reaching the parent security logic with an emptied body.


OpenCVE Recommended Actions

  • Apply the MISP patch that introduces __rejectUnsafeMethodOverride() in BetterSecurityComponent::startup() to reject any non‑write method override before the parent SecurityComponent runs
  • Update the MISP instance to version 2.5.46 or later where the fix is included
  • Verify that any custom security modules or configurations do not re‑introduce method‑override processing that could bypass CSRF checks

Generated by OpenCVE AI on September 17, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the normal write verbs POST, PUT, PATCH, and DELETE, CakePHP also clears the parsed request body. MISP’s security component then determines whether to perform _validatePost() and _validateCsrf() based on whether request data remains. With a value such as: _method=GET the body becomes empty before those checks run, so both protections are skipped. A cross-site form containing only that override can therefore reach actions whose parameters are taken from the URL rather than the request body Version affected: ≤2.5.45
Title MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent
Weaknesses CWE-20
CWE-352
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T14:37:05.161Z

Reserved: 2026-09-15T07:41:29.630Z

Link: CVE-2026-91819

cve-icon Vulnrichment

Updated: 2026-09-15T14:35:09.673Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T08:17:07.333

Modified: 2026-09-16T13:42:48.930

Link: CVE-2026-91819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)