CVE-2026-39962Disclosure(misp-project / misp)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch misp-project misp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTE_USER (such as in certain proxy setups). An attacker able to control that value can manipulate the LDAP search filter and potentially bypass authentication constraints or cause unauthorized LDAP queries. This vulnerability is fixed in 2.5.36.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • misp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
misp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-05-04: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-04-09: 104-0905-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-05-041
Patch1
Full discourse2 posts
  • S2GRUPO@s2grupo
    Patch

    CVE-2026-39962 corresponde a un fallo crítico de seguridad identificado en la plataforma MISP (Malware Information Sharing Platform), ampliamente utilizada para el intercambio de inteligencia de amenazas. Se recomienda actualizar a MISP 2.5.36 o superior https://hubs.la/Q04dKcZl0

    Post summary

    CVE-2026-39962 is a critical flaw in MISP; the advisory recommends upgrading to version 2.5.36 or later to mitigate the vulnerability.

    00020143
    5.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39962 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.p… https://www.cve.org/CVERecord?id=CVE-2026-39962

    Post summary

    The tweet announces CVE‑2026‑39962, a vulnerability in MISP related to LDAP query sanitization, and notes that the issue is fixed in version 2.5.36.

    00000102
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmisp-projectmisp---

Explore more