CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-106513: MISP 0 through 2.5.48

Affected technology

MISP · 0 through 2.5.48
MISP

Component: Server settings (app/Model/Server.php), MISP.redis_host, Plugin.ZeroMQ_redis_host, SimpleBackgroundJobs.redis_host, download_attachments_on_load
File: app/Model/Server.php

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · High privileges required · No user interaction required

What an attacker can do

The attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Source advisory’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and availability impact as none; integrity impact as high.

Published

CWE
CWE-284, CWE-749
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-106513.html