CVE-2026-95693
📛 CVE Title
MISP Information Disclosure via Forged Upload Path
Description
In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type. This constitutes an information disclosure vulnerability: the server's filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access. The vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CIRCL
- CVSS severity
- MEDIUM
- CVSS score
- 5.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N- Effective score
- 5.3 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-200,CWE-22 - Reserved
- 2026-09-22
- Published
- 2026-09-22 14:22 UTC
- Last updated
- 2026-09-22 15:09 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95693.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 15:17:27 UTC
- NVD last modified
- 2026-09-22 16:18:23 UTC
NVD / KEV / EPSS data refreshed 2026-09-23 02:29 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84492 - Assigner
- CIRCL
- Published
- Sep 22, 2026, 2:22:28 PM
- Updated
- Sep 22, 2026, 3:09:48 PM
- EUVD base score (CVSS 4.0)
-
5.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- MISP
- Products
-
MISP (0 <2.5.47)
- Aliases
-
GHSA-f496-75v4-rv5q
ENISA description: In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type. This constitutes an information disclosure vulnerability: the server's filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access. The vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MISP | MISP |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security patch patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/MISP/MISP/commit/9a2a4acfe 5a6e4751-2f3f-4070-9419-94fb35b644e8
Remediations (10)
-
web:blog.talosintelligence.com
Microsoft has released its monthly security update for September 2026 , which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical." Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild: CVE - 2026 -81963 affects Windows Update Stack. CVE - 2026 -81963 is a elevation of privilege vulnerability ...
2026-09-23 15:40 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-23 15:40 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-23 15:40 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:40 UTC -
web:socradar.io
CVE - 2026 -69836: Microsoft Entra ID RCE Fixed Microsoft recently disclosed CVE - 2026 -69836, a critical Remote Code Execution (RCE) vulnerability in Microsoft Entra ID (formerly Azure Active Directory). Because this issue affected a Microsoft-hosted cloud service, remediation was applied on the backend rather than through a traditional customer patch . In this post, we explore what CVE - 2026 -69836 ...
2026-09-23 15:40 UTC -
web:support.microsoft.com
This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5121768) is cumulative. It includes all improvements from previous security and non-security updates, along with an additional fix . Improvements This OOB update includes the following improvement: [System Performance] This update addresses an issue affecting a limited number of devices with an Intel ...
2026-09-23 15:40 UTC -
web:support.sap.com
SAP Security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 8 th of September 2026 , SAP security patch day saw the release of 19 new security notes. There is 1 update to ...
2026-09-23 15:40 UTC -
web:vulmon.com
Information Disclosure in MISP via Arbitrary Path Probing. Authenticated users with the 'perm_add' permission in MISP can discover files on the server's…
2026-09-23 15:40 UTC -
web:www.messageware.com
Microsoft's September 2026 Exchange Server security updates patch 9 vulnerabilities, including a 9.3-severity spoofing flaw.
2026-09-23 15:40 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-09-23 15:40 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-95693.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95693",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:09:40.847048Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:48.685Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"EventReport"
],
"product": "MISP",
"programFiles": [
"app/Model/EventReport.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type. </p><p>This constitutes an information disclosure vulnerability: the server's filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access. </p><p>The vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host.</p>"
}
],
"value": "In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission could supply an arbitrary filesystem path as the tmp_name value. The application would then probe that path and return distinct validation error messages depending on whether the file existed, its MIME type, or its image format. By observing the differing error responses, an attacker could enumerate the existence of files at arbitrary paths on the MISP server and determine their type.\u00a0\n\nThis constitutes an information disclosure vulnerability: the server's filesystem layout and file types are leaked to any user with the perm_add role without requiring administrative access.\u00a0\n\nThe vulnerability does not allow reading file contents, writing files, or executing code, but it can aid further attacks by revealing sensitive file locations (e.g., configuration files, private keys, or other artifacts) present on the host."
}
],
"impacts": [
{
"capecId": "CAPEC-177",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-177 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:22:28.896Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9a2a4acfe"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration.</p>"
}
],
"value": "The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration."
}
],
"title": "MISP Information Disclosure via Forged Upload Path",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 49 commits after fix), suggesting versions prior to the fix commit are vulnerable. No explicit version range is stated in the patch.",
"PR:L is assumed because the commit message specifies 'any perm_add user', which is a non-admin role in MISP. The exact privilege level mapping to CVSS PR is an assumption.",
"VC:L is assigned because the disclosure is limited to file existence and type metadata, not full file contents. If the information disclosed is considered more sensitive in a specific deployment, VC could be rated higher.",
"CAPEC-177 (Path Traversal) is the closest available pattern; the actual impact is an information-disclosure oracle rather than a full traversal read, so the mapping is approximate.",
"The Co-Authored-By line credits an AI assistant (Claude Opus 4.8) as a remediation developer. This is recorded as supplied in the metadata but is atypical for CVE credit."
],
"capecRationale": [
{
"capecId": "CAPEC-177",
"rationale": "The attacker manipulates the tmp_name parameter to reference file paths outside the intended upload directory, causing the server to probe arbitrary locations. Although the observable effect is information disclosure rather than full file read, the mechanism is path traversal: the application uses an untrusted path string to access the filesystem. CAPEC-177 is the closest available pattern; the uncertainty is that the impact is limited to metadata disclosure rather than full traversal read, but no more specific CAPEC exists for 'path probing via error-message oracle'."
}
],
"commit": "9a2a4acfe71eaacfe9305a89483d45772edf16b4",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N: MISP is a web application accessed over the network. AC:L: The attack requires only crafting a request with a different tmp_name value; no race conditions or complex setup are needed. AT:N: No prior user interaction or attack complexity beyond the request is required. PR:L: The attacker needs an authenticated account with the perm_add permission, which is a low-privilege role in MISP (not admin). UI:N: No victim interaction is required. VC:L: File existence and type information is disclosed, but file contents are not readable. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No impact on subsequent components.",
"fixSummary": "The fix introduces an early validation gate in EventReport::uploadPicture that checks is_uploaded_file() on the supplied tmp_name before any filesystem-probing functions (file_exists, mime_content_type, exif_imagetype) are invoked. If the value is not a genuine PHP upload, the method immediately returns a generic error message, preventing the attacker from using the endpoint as an oracle for filesystem enumeration.",
"generatedAt": "2026-09-22T14:16:43.440374Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0a64cbcd67009e5af0b74721071bfaf4a36c3cac59e13128eaae04545009886a",
"patchSummary": "In app/Model/EventReport.php, eight lines are inserted at the top of the upload-processing block (after the size/error check). The added code verifies that $picture['tmp_name'] is non-empty and passes is_uploaded_file(). If either condition fails, a generic 'File was not uploaded correctly' error is appended to $saveResult['errors'] and the function returns early, before pathinfo, file_exists, mime_content_type, or exif_imagetype are ever called on the untrusted path.",
"patchTruncated": false,
"patches": [
{
"commit": "9a2a4acfe71eaacfe9305a89483d45772edf16b4",
"patchSha256": "0a64cbcd67009e5af0b74721071bfaf4a36c3cac59e13128eaae04545009886a",
"source": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"subject": "fix: [security] Reject a forged upload path in the"
}
],
"source": "https://github.com/MISP/MISP/commit/9a2a4acfe.patch",
"subject": "fix: [security] Reject a forged upload path in the",
"tagVersionBoundary": {
"commits_after_fix": 49,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-200",
"rationale": "The primary security impact is the disclosure of filesystem state (file existence and type) through distinct error messages, which is a classic information exposure weakness. The attacker does not read file contents but learns metadata about arbitrary paths."
},
{
"cweId": "CWE-22",
"rationale": "The caller-supplied tmp_name was used as a filesystem path without restricting it to the upload directory. Although the impact here is information disclosure rather than full file read/write, the root cause is the lack of path restriction, making CWE-22 a contributing weakness."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20218"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95693",
"datePublished": "2026-09-22T14:22:28.896Z",
"dateReserved": "2026-09-22T14:22:26.180Z",
"dateUpdated": "2026-09-22T15:09:48.685Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}