Description
Affected versions of MISP expose several state-changing controller actions without restricting them to POST.


The affected actions are:



 - EventReportsController::purgeUnusedPictures()

 - NoticelistsController::enableNoticelist()

 - ServersController::removeOrphanedCorrelations()

 - WorkflowsController::rebuildRedis()






The patch adds allowMethod(['post']) to each action, preventing them from being triggered through ordinary GET requests.


For purgeUnusedPictures(), the corresponding UI previously used $.get(). The fix converts that request to POST and supplies X-CSRF-Token, while the controller enables header-only CSRF validation for that AJAX action.


Because GET requests can be induced cross-origin through links, images, redirects, or navigation, accepting GET for these state-changing operations can let an attacker trigger them using the authenticated victim's session.

Version affected: ≤2.5.45
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unintended state‑changing actions via CSRF
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exposes several controller actions in MISP that can be invoked by a GET request made under an authenticated session. Because GET requests can be induced cross‑origin through links, images, redirects, or navigation, an attacker can trigger these actions with the victim’s authenticated session.

Affected Systems

The affected vendor is MISP, and the product is the MISP platform. Versions up to and including 2.5.45 are impacted. Users should check that their installation is on a release newer than 2.5.45.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity, and the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a classic CSRF attack that relies on a malicious web page or embedded content to make a GET request to a state‑changing endpoint while the victim is logged into MISP.

Generated by OpenCVE AI on September 17, 2026 at 17:57 UTC.

Remediation

Vendor Solution

The vulnerability is remediated by restricting all four state-changing actions to accept only POST requests via the CakePHP allowMethod() guard. Additionally, the client-side JavaScript for purgeUnusedPictures is updated to issue a POST request with the page's CSRF token in the X-CSRF-Token header, and a beforeFilter() hook is added to EventReportsController to configure header-only CSRF token validation for that specific action, since it is invoked via hand-built AJAX rather than a rendered form.


OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.46 or newer or apply the official patch commit b4a5486b5 that restricts the relevant actions to POST only.
  • Replace any front‑end AJAX calls that target purgeUnusedPictures() to use POST requests with the X‑CSRF‑Token header.
  • If custom code or external scripts still make GET requests to these endpoints, update them to CSRF risk.

Generated by OpenCVE AI on September 17, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  - ServersController::removeOrphanedCorrelations()  - WorkflowsController::rebuildRedis() The patch adds allowMethod(['post']) to each action, preventing them from being triggered through ordinary GET requests. For purgeUnusedPictures(), the corresponding UI previously used $.get(). The fix converts that request to POST and supplies X-CSRF-Token, while the controller enables header-only CSRF validation for that AJAX action. Because GET requests can be induced cross-origin through links, images, redirects, or navigation, accepting GET for these state-changing operations can let an attacker trigger them using the authenticated victim's session. Version affected: ≤2.5.45
Title MISP: State-changing actions accessible via GET request enabling CSRF
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T13:19:25.134Z

Reserved: 2026-09-15T09:14:39.778Z

Link: CVE-2026-91857

cve-icon Vulnrichment

Updated: 2026-09-15T13:15:10.819Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T10:17:06.267

Modified: 2026-09-16T13:42:48.977

Link: CVE-2026-91857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)