CVE-2026-104900
Deferred Deferred - Pending Action

Stored XSS in MISP Remote Event Preview

Vulnerability report for CVE-2026-104900, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server could craft an event identifier containing HTML or JavaScript markup. When a user on the local MISP instance views the remote event preview index, the unescaped value is rendered directly in the browser, allowing arbitrary script execution in the victim's session. Preconditions: - A linked/remote MISP server is configured and connected to the local instance. - The attacker has sufficient access on the linked server to create or modify an event with a crafted identifier. - A victim user on the local instance views the remote event preview index page. Impact: - Execution of arbitrary JavaScript in the context of the MISP web application. - Potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of the authenticated user. Affected versions: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a stored cross-site scripting (XSS) vulnerability in the remote event preview feature. The issue occurs because the count field's value in the index table is rendered without proper HTML encoding, even though the associated link URL is escaped. An attacker with access to a linked MISP server can craft an event identifier containing malicious scripts. When a local user views the remote event preview, the unescaped value executes arbitrary JavaScript in their browser session.

Detection Guidance

Check MISP version with 'misp --version' or via the web interface. If version is below 2.5.48, the system is vulnerable. Inspect event identifiers in remote event previews for unusual HTML or JavaScript content.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary JavaScript in your MISP session. This could lead to session hijacking, where the attacker steals your session cookies and gains unauthorized access to your account. It may also enable data exfiltration, where sensitive information is sent to the attacker, or allow the attacker to perform actions on your behalf without your consent.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's principles of data protection and user privacy. For HIPAA, it may result in unauthorized disclosure of protected health information, breaching compliance requirements. Both regulations mandate strict controls to prevent such breaches, and this vulnerability undermines those controls.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later immediately. If immediate upgrade is not possible, disable remote event preview functionality or restrict access to linked MISP servers until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104900. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart