CVE-2026-104906
Deferred Deferred - Pending Action

XSS in MISP TAXII Object Viewer

Vulnerability report for CVE-2026-104906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in MISP's TAXII object viewer. When displaying remote TAXII objects, the JSON content of string properties was rendered directly into an HTML pre block without proper encoding. This allows attackers to inject malicious HTML or JavaScript into the victim's MISP session by controlling the content of a TAXII object.

Detection Guidance

To detect this vulnerability, check if your MISP instance is running a version prior to 2.5.48. Inspect TAXII object viewer pages for unescaped JSON content in HTML pre blocks. Look for suspicious JavaScript execution in the browser console when viewing TAXII objects.

Impact Analysis

An attacker could execute arbitrary JavaScript in your browser within the MISP application context. This could lead to theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. It may also allow the attacker to perform actions on your behalf while you are authenticated.

Mitigation Strategies
  • Upgrade MISP to version 2.5.48 or later to apply the security fix.
  • Review and remove any untrusted TAXII feeds or objects that could be malicious.
  • Monitor network traffic for unusual activity from MISP instances.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104906. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart