CVE-2026-103662
Deferred Deferred - Pending Action

Reflected XSS in MISP Legacy Taxonomy Tag Management

Vulnerability report for CVE-2026-103662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session. Preconditions: - The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled. - The victim must be an authenticated site administrator. - The victim must navigate to the attacker-crafted URL (e.g., via a phishing link). Security impact: - Execution of arbitrary client-side script in the context of the administrator's browser. - Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page. - Potential for performing privileged actions on behalf of the administrator within the MISP interface. Affected versions: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in MISP affecting legacy taxonomy tag management forms. It occurs when a user-supplied tag name in a URL is echoed unescaped into the HTML output. An attacker can craft a malicious URL that, when visited by an admin, executes arbitrary JavaScript in their browser session.

Detection Guidance

To detect this vulnerability, check if your MISP instance is running a version older than 2.5.48. Inspect the legacy taxonomy tag confirmation forms (add tag and disable tag) for unescaped user-supplied tag name parameters in the rendered HTML output. Review server logs for suspicious URLs containing tag name parameters.

Impact Analysis

An attacker could steal session tokens, CSRF tokens, or other sensitive data from the admin's browser. They could also perform privileged actions on behalf of the admin within MISP. The attack requires tricking an admin into visiting a crafted URL, typically via phishing.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, such as session tokens or CSRF tokens, which may violate GDPR's data protection principles or HIPAA's safeguards for protected health information if such data is exposed.

Mitigation Strategies

Immediately upgrade MISP to version 2.5.48 or later to apply the fix. Disable the legacy taxonomy tag confirmation views if they are not required. Ensure site administrators avoid clicking on untrusted links and enable Content Security Policy (CSP) headers to mitigate XSS risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103662. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart