CVE-2026-104901
Deferred Deferred - Pending Action

XSS in MISP ID Translator via Remote Event ID

Vulnerability report for CVE-2026-104901, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output encoding. A malicious or compromised linked server could return a crafted event ID containing arbitrary HTML or JavaScript markup. This markup would be rendered in the browser of any user in the host organization who views the ID Translator page, enabling session hijacking, credential theft, or other client-side attacks. Preconditions: - The victim must be an authenticated user of the host MISP instance. - A linked server must be configured on the host instance. - The victim must navigate to the ID Translator page for a given event. Affected versions: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a cross-site scripting (XSS) vulnerability in its ID Translator feature. When a user views the ID Translator page, the application requests event identifiers from linked remote MISP servers. If a malicious or compromised server returns a crafted event ID containing HTML or JavaScript, it could be executed in the browser of any authenticated user who views the page. This could lead to session hijacking or credential theft.

Detection Guidance

To detect this XSS vulnerability in MISP, check if your instance is running an affected version (<2.5.48). Inspect the ID Translator page for improperly rendered event IDs from linked servers. Look for HTML or JavaScript markup in event IDs that should only contain numeric values.

Impact Analysis

If you are an authenticated MISP user with a linked server configured, visiting the ID Translator page could expose you to session hijacking or credential theft. An attacker could steal your session cookies or login credentials through malicious scripts injected via the event ID.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's security rules. A breach could result in data exposure, unauthorized access, or loss of confidentiality, triggering compliance violations and legal consequences.

Mitigation Strategies

Immediately upgrade MISP to version 2.5.48 or later. Disable any untrusted linked MISP servers until they are verified to be patched. Review and sanitize all event IDs from remote servers before rendering them in the ID Translator page.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104901. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart