OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94401

HIGH · CVSS 8.3 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

MISP has a file-handling vulnerability that allows authenticated users with modify permissions to bypass XML validation, enabling them to upload malicious files containing local file paths or URLs. This could lead to unauthorized access to sensitive local files and internal network services, posing a significant risk to the confidentiality and integrity of the organization's data. Organizations using MISP versions prior to 2.5.47 should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94401
Severity
HIGH
CVSS
8.3
EPSS
0.38%

Original NVD Description

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with permission to modify data could upload a file containing a local file path or a web address instead. If a local file path was supplied, MISP could read that file from the server. If a URL was supplied, MISP could make a request to that address, including systems that may only be reachable from inside the organization’s network. The vulnerability could therefore expose sensitive local files and allow unauthorized requests to internal services. Exploitation required a valid MISP account with modify permissions, but no additional user interaction was needed. Version affected: <2.5.47