MISP is a specialized threat-intelligence platform and malware-information-sharing framework widely deployed across government, financial, and security operations organizations, where its role as a centralized intelligence hub creates a high-impact attack surface despite a narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though confirmed in-the-wild exploitation and public exploit availability remain limited. The exposure recurs across the core MISP platform and its integrations such as the Maltego connector, clustering around web-layer input-handling weaknesses—particularly cross-site scripting and authorization failures—alongside deserialization flaws that reflect the data-import and inter-system communication demands of a multi-user intelligence platform. Defenders should prioritize this vendor's disclosures given the sensitivity of intelligence data and the credential or access-control consequences of compromise; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Misp over time
Signals from CVEs in this vendor scope (143 CVEs).
143 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19908HIGH An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulne | Dec 6, 2018 | 8.8 | 46 | NO | YES |
CVE-2026-10611CRITICAL An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Sec | Jun 2, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-56423HIGH MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using br | Jun 22, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-56425HIGH The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important secu | Jun 22, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-56422CRITICAL Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_ | Jun 22, 2026 | 9.4 | 36 | NO | NO |
CVE-2026-56424HIGH MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on w | Jun 22, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-10868CRITICAL A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit re | Jun 4, 2026 | 9.0 | 35 | NO | NO |
CVE-2026-44381MEDIUM MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in th | May 13, 2026 | 5.3 | 33 | NO | YES |
CVE-2026-56447HIGH MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passe | Jun 22, 2026 | 7.2 | 32 | NO | NO |
CVE-2026-56446HIGH MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled conten | Jun 22, 2026 | 7.2 | 32 | NO | NO |
Signals from CVEs in this vendor scope (143 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Misp.
Media articles that mention a CVE ID that affects a product developed by Misp — matched by CVE ID, not by vendor name.