Skip to main content
Vulnerability Database/CVE-2026-106513

CVE-2026-106513: MISP Redis Configuration RCE Vulnerability

CVE-2026-106513 is a remote code execution flaw in MISP that lets attackers exploit Redis configuration settings via compromised site-admin sessions. This article covers the technical details, exploitation chain, and mitigation strategies.

Published:

CVE-2026-106513 Overview

CVE-2026-106513 affects Malware Information Sharing Platform (MISP), an open-source threat intelligence platform. The vulnerability exposes Redis host configuration settings for the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin through the MISP web UI and API to site-admin users. Background job workers trust raw Redis job payloads without additional validation. An attacker with a hijacked site-admin session can redirect workers to an attacker-controlled Redis instance and inject malicious job payloads, achieving arbitrary command execution as the worker account. The flaw is categorized under [CWE-284] Improper Access Control.

Critical Impact

Remote code execution in the context of the MISP worker process, with potential for data exfiltration through the attacker-controlled Redis connection.

Affected Products

  • MISP (Malware Information Sharing Platform) core application
  • MISP ZeroMQ plugin
  • MISP SimpleBackgroundJobs plugin

Discovery Timeline

  • 2026-10-06 - CVE-2026-106513 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-106513

Vulnerability Analysis

MISP exposes three Redis host configuration settings through the administrative web UI and API: the core application Redis host, the ZeroMQ plugin Redis host, and the SimpleBackgroundJobs plugin Redis host. These settings govern where MISP background workers fetch job payloads. Workers deserialize and execute these job payloads without validating their origin or integrity.

The download_attachments_on_load setting, which controls inline attachment rendering, was also modifiable through the same interface. Re-enabling this setting through a hijacked session facilitates further client-side attacks against analysts.

Exploitation requires an authenticated site-admin session plus a prior session-compromise mechanism such as stored cross-site scripting. The attack culminates in arbitrary command execution as the MISP worker user, which typically has access to the threat intelligence database and attachment storage.

Root Cause

The root cause is improper access control over infrastructure configuration. Settings that control trust boundaries, specifically Redis endpoints for job queues, were classified as runtime-mutable options available through the web interface rather than command-line-only (cli_only) settings. Combined with the workers' implicit trust of the Redis job queue contents, this allowed a web-tier compromise to pivot into code execution on the worker tier.

Attack Vector

An attacker first obtains a site-admin session, typically through a stored XSS payload or session hijacking. They use the administrative API to update the Redis host for the core, ZeroMQ, or SimpleBackgroundJobs plugin to an attacker-controlled server. After restarting the workers, the workers connect to the malicious Redis instance and consume crafted job payloads that execute arbitrary commands as the worker account.

php
// Patch excerpt from app/Model/Server.php
                     'value' => true,
                     'test' => 'testBool',
                     'type' => 'boolean',
+                    'cli_only' => true,
                 ),
                 'osuser' => array(
                     'level' => 0,

Source: MISP commit 2ebf29f93. The patch marks the affected configuration keys as cli_only, preventing modification through the web UI or API.

Detection Methods for CVE-2026-106513

Indicators of Compromise

  • Unexpected changes to Redis host values in MISP configuration audit logs for the core, ZeroMQ, or SimpleBackgroundJobs plugins.
  • MISP worker processes establishing outbound TCP connections to Redis endpoints (typically port 6379) outside the organization's known infrastructure.
  • Restart events for MISP background workers that correlate with recent site-admin configuration changes.
  • Re-enablement of the download_attachments_on_load setting without an associated change ticket.

Detection Strategies

  • Monitor MISP audit logs for Server.php setting modifications, particularly keys ending in host, port, or redis_host.
  • Alert on child processes spawned by MISP worker accounts that are not part of the normal job execution profile (shells, interpreters, network utilities).
  • Correlate site-admin session activity with configuration write operations against the /servers/serverSettingsEdit endpoint.

Monitoring Recommendations

  • Baseline the expected Redis endpoints for each MISP instance and alert on any deviation at the network layer.
  • Enable verbose logging of MISP API calls and forward them to a central analytics platform for correlation with authentication events.
  • Review site-admin session lifetimes and investigate sessions originating from unusual IP addresses or user agents.

How to Mitigate CVE-2026-106513

Immediate Actions Required

  • Apply the upstream MISP patch that marks the Redis host and attachment download settings as cli_only.
  • Audit recent site-admin activity and configuration changes for unauthorized modification of Redis host values.
  • Rotate site-admin credentials and invalidate active sessions if any suspicious activity is identified.
  • Restrict network egress from MISP worker hosts to only approved Redis endpoints.

Patch Information

The fix is available in the MISP repository as commit 2ebf29f93. The patch adds 'cli_only' => true to the affected server settings so they can only be changed from the command line. See the MISP security commit for the full diff.

Workarounds

  • Enforce strict Content Security Policy headers on the MISP web interface to reduce the risk of stored XSS leading to session hijacking.
  • Place MISP administrative endpoints behind an authenticating reverse proxy or VPN restricted to administrator workstations.
  • Use host-based firewall rules on MISP worker servers to allow Redis connections only to the local or trusted Redis host.
  • Disable the download_attachments_on_load setting and verify its state after any configuration change.
bash
# Verify affected settings are marked cli_only after patching
grep -n "cli_only" /var/www/MISP/app/Model/Server.php | grep -iE "redis|download_attachments_on_load"

# Restrict outbound Redis connections from worker host (example)
iptables -A OUTPUT -p tcp --dport 6379 ! -d 127.0.0.1 -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.