CVE-2026-106513
Deferred Deferred - Pending Action

Arbitrary Code Execution in MISP via Redis Configuration Manipulation

Vulnerability report for CVE-2026-106513, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: CIRCL

Description

MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the download_attachments_on_load setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MISP MISP 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP exposes Redis host addresses and background job worker settings to site-admin users via its web UI and API. An attacker with a hijacked site-admin session can modify these settings to point to a malicious Redis server, inject malicious job payloads, and achieve arbitrary command execution as the worker account. The vulnerability requires site-admin privileges and a prior session compromise.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized modifications to Redis host settings and worker configurations in MISP. Review MISP's web UI and API logs for changes to Redis host addresses or the download_attachments_on_load setting by site-admin users. Inspect worker processes for unexpected connections to external Redis servers.

Impact Analysis

This vulnerability allows remote code execution in the context of the MISP worker process. An attacker could execute arbitrary commands, potentially leading to data exfiltration, system compromise, or further lateral movement within the network.

Mitigation Strategies

Immediately restrict site-admin access to trusted users only. Disable the download_attachments_on_load setting if enabled. Monitor and audit all changes to Redis host configurations and worker settings. Ensure Redis instances are not exposed to untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106513. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart