Description
MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working, --working, -root, --root, -webroot, --webroot) and uses the following element as the application root. The events/contact endpoint passes user-controlled fields (message and person) into job arguments without validation. An attacker who can submit the contact form can set the person field to a reserved switch and the message field to a phar:// URI pointing to a malicious archive. The CakePHP bootstrap then includes Config/core.php from within that archive, executing attacker-controlled PHP code with the privileges of the web user. 

The vulnerability requires the ability to submit the events/contact form (or any other endpoint that forwards user input into background job arguments). No special timing or race condition is required; the attack is deterministic once the crafted parameters are accepted. The impact is full remote code execution in the context of the MISP web server process, allowing data exfiltration, persistence, and lateral movement within the host.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in MISP’s background job dispatch mechanism allows an attacker who can submit the events/contact form to inject a reserved CakePHP console switch into the job argument list. The vulnerability originates from job arguments being passed directly as the argv array to the CakePHP console process, where ShellDispatcher::_parsePaths scans the entire argv for path switches such as -app, --app, -working, --working, -root, --root, -webroot, and --webroot. By setting the 'person' field to one of these switches and the 'message' field to a phar:// URI pointing to a malicious archive, the attacker causes the CakePHP bootstrap to load Config/core.php from that archive and execute attacker‑controlled PHP code with the privileges of the MISP web user. This provides full remote code execution on the host, enabling data exfiltration, persistence, and lateral movement. The exploit is deterministic once the crafted parameters are accepted; no special timing or race condition is required and the attack can be performed by anyone able to submit the events/contact endpoint.

Affected Systems

The issue impacts the open‑source MISP platform; no specific product versions are listed in the CNA data, so any deployment that has not applied the referenced patch (commit 120813344) remains vulnerable.

Risk and Exploitability

The CVSS score is 8.7, indicating high impact. EPSS is below 1 %, showing very low probability of public exploitation so far, and the vulnerability is not in the CISA KEV catalog. An attacker requires the ability to submit the events/contact endpoint or any other endpoint that forwards user input into background job arguments. No timing or race condition is needed; once the crafted parameters are accepted the exploit is deterministic.

Generated by OpenCVE AI on September 22, 2026 at 10:06 UTC.

Remediation

Vendor Solution

The fix introduces a validation layer in BackgroundJobsTool::enqueue() that rejects any job argument matching a reserved CakePHP console path switch (-app, --app, -working, --working, -root, --root, -webroot, --webroot), throwing an InvalidArgumentException before the job is queued. Additionally, the EventsController::contact() method now casts the person field to a boolean, preventing it from ever forming a switch/value pair with the adjacent message field. Together, these changes ensure that user-supplied data can never be interpreted as a console path directive by the worker process.


OpenCVE Recommended Actions

  • Apply the latest MISP release that contains commit 120813344, which validates background job arguments and casts the person field to boolean.
  • Restrict or disable the events/contact endpoint to eliminate the user‑controlled input vector if an upgrade cannot be performed immediately.
  • Block or filter phar:// URI usage at the PHP level (e.g., disable allow_url_include) to reduce the attack surface while the patch is pending.

Generated by OpenCVE AI on September 22, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working, --working, -root, --root, -webroot, --webroot) and uses the following element as the application root. The events/contact endpoint passes user-controlled fields (message and person) into job arguments without validation. An attacker who can submit the contact form can set the person field to a reserved switch (e.g., -app) and the message field to a phar:// URI pointing to a malicious archive. The CakePHP bootstrap then includes Config/core.php from within that archive, executing attacker-controlled PHP code with the privileges of the web user. The vulnerability requires the ability to submit the events/contact form (or any other endpoint that forwards user input into background job arguments). No special timing or race condition is required; the attack is deterministic once the crafted parameters are accepted. The impact is full remote code execution in the context of the MISP web server process, allowing data exfiltration, persistence, and lateral movement within the host. MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working, --working, -root, --root, -webroot, --webroot) and uses the following element as the application root. The events/contact endpoint passes user-controlled fields (message and person) into job arguments without validation. An attacker who can submit the contact form can set the person field to a reserved switch and the message field to a phar:// URI pointing to a malicious archive. The CakePHP bootstrap then includes Config/core.php from within that archive, executing attacker-controlled PHP code with the privileges of the web user.  The vulnerability requires the ability to submit the events/contact form (or any other endpoint that forwards user input into background job arguments). No special timing or race condition is required; the attack is deterministic once the crafted parameters are accepted. The impact is full remote code execution in the context of the MISP web server process, allowing data exfiltration, persistence, and lateral movement within the host.
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher::_parsePaths() scans the entire argv for path switches (-app, --app, -working, --working, -root, --root, -webroot, --webroot) and uses the following element as the application root. The events/contact endpoint passes user-controlled fields (message and person) into job arguments without validation. An attacker who can submit the contact form can set the person field to a reserved switch (e.g., -app) and the message field to a phar:// URI pointing to a malicious archive. The CakePHP bootstrap then includes Config/core.php from within that archive, executing attacker-controlled PHP code with the privileges of the web user. The vulnerability requires the ability to submit the events/contact form (or any other endpoint that forwards user input into background job arguments). No special timing or race condition is required; the attack is deterministic once the crafted parameters are accepted. The impact is full remote code execution in the context of the MISP web server process, allowing data exfiltration, persistence, and lateral movement within the host.
Title MISP Background Job Argument Injection via Console Path Switches Enables Remote Code Execution
Weaknesses CWE-20
CWE-74
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-22T07:42:13.496Z

Reserved: 2026-09-17T16:25:37.686Z

Link: CVE-2026-93295

cve-icon Vulnrichment

Updated: 2026-09-17T18:09:23.341Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:18:17.053

Modified: 2026-09-22T08:16:41.520

Link: CVE-2026-93295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T10:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')