Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses two critical MISP Core vulnerabilities: CVE‑2026‑56423, a broken access‑control flaw permitting bulk deletions across organizations, and CVE‑2026‑56447, an RCE path via rdkafka configuration.
CERT-PY@CERTpyDisclosure
The post announces three CVEs affecting MISP products and directs readers to additional information via a linked webpage. It does not provide technical details, exploits, or mitigation guidance.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces the discovery of an arbitrary code execution vulnerability in MISP, triggered via a Kafka configuration path traversal attack. No exploit code, active exploitation, or patch information is provided.
Infoflowcloud@infoflowcloudDisclosure
The post discloses CVE-2026-56447, noting that authenticated MISP admins can point Kafka_rdkafka_config to an arbitrary filesystem path, potentially leading to unauthorized configuration changes.
CVE@CVEnewDisclosure
The post discloses a vulnerability in MISP where an authenticated administrator can set Kafka_rdkafka_config to an arbitrary filesystem path, enabling potential exploitation. No PoC, exploit, patch, or evidence of active usage is referenced.