CVE-2026-56447Disclosure(misp-project / misp)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka options such as plugin.library.paths to load an external library, resulting in arbitrary code execution with the privileges of the MISP process. An attacker could leverage a MISP-writable location, such as an uploaded file or administrative image, to host the malicious configuration file. The issue is fixed by restricting the setting to absolute .ini files located only in approved configuration directories outside the webroot and MISP upload targets.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • misp

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-06-22); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
misp

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-22: 4Mentions · 2026-07-06: 1Technical Details · 2026-06-22: 406-2207-06
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-224
Disclosure4
2026-07-061
Disclosure1
Full discourse5 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos MISP ❗ CVE-2026-56447 ❗ CVE-2026-56423 ❗ CVE-2026-56422 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-misp/ https://t.co/VkJ11jLE4b

    Post summary

    The post announces three CVEs affecting MISP products and directs readers to additional information via a linked webpage. It does not provide technical details, exploits, or mitigation guidance.

    00030287
    6.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Two MISP Core Flaws: Broken Access Control in Bulk Deletion + rdkafka Config RCE (CVE-2026-56423, CVE-2026-56447) MISP Core, the open-source threat-intelligence sharing platform, was hit by two critical issues. CVE-2026-56423 is a broken access-control flaw in the bulk deletion (deleteSelection) flows for Event Reports and Sharing Groups: the handlers authorized deletion using broad role-level permissions instead of per-object ownership checks, so a contributor- or sharing-group-capable user could hard-delete reports and sharing groups belonging to other organisations instance-wide. CVE-2026-56447 is an arbitrary code execution flaw: an authenticated site admin could point the Kafka_rdkafka_config setting at an arbitrary INI file, and rdkafka options such as plugin.library.paths would load an external library, running code with the MISP process's privileges. An attacker could stage the malicious config in a MISP-writable location like an uploaded file. 👉Affected: MISP <= 2.5.41.

    Post summary

    The post discloses two critical MISP Core vulnerabilities: CVE‑2026‑56423, a broken access‑control flaw permitting bulk deletions across organizations, and CVE‑2026‑56447, an RCE path via rdkafka configuration.

    00001110
    226 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56447 Arbitrary Code Execution in MISP via Kafka Configuration Path Traversal https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56447

    Post summary

    The text announces the discovery of an arbitrary code execution vulnerability in MISP, triggered via a Kafka configuration path traversal attack. No exploit code, active exploitation, or patch information is provided.

    00000125
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56447 MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI … https://www.cve.org/CVERecord?id=CVE-2026-56447 ----- Traducción: CVE-2026-56447 MIS… http://infoflow.cloud`

    Post summary

    The post discloses CVE-2026-56447, noting that authenticated MISP admins can point Kafka_rdkafka_config to an arbitrary filesystem path, potentially leading to unauthorized configuration changes.

    0000042
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56447 MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI … https://www.cve.org/CVERecord?id=CVE-2026-56447

    Post summary

    The post discloses a vulnerability in MISP where an authenticated administrator can set Kafka_rdkafka_config to an arbitrary filesystem path, enabling potential exploitation. No PoC, exploit, patch, or evidence of active usage is referenced.

    00000892
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmisp-projectmisp---

Explore more