Skip to main content
Vulnerability Database/CVE-2026-95659

CVE-2026-95659: MISP XSS Vulnerability in AnalystData

CVE-2026-95659 is a reflected cross-site scripting vulnerability in MISP that enables authenticated attackers to inject malicious JavaScript through crafted URLs. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-95659 Overview

CVE-2026-95659 is a reflected cross-site scripting (XSS) vulnerability in Malware Information Sharing Platform (MISP) versions prior to 2.5.47. The flaw resides in the AnalystDataController::viewForObject action, which accepts a parent object type parameter from the URL without validation. The value is passed to the Overmind-themed AnalystData thread view element and interpolated into translated strings that render into the HTML response without output encoding. An authenticated attacker who tricks a victim into visiting a crafted URL can execute arbitrary JavaScript in the victim's browser within the MISP application context [CWE-20].

Critical Impact

Successful exploitation allows session data theft, page manipulation, and unauthorized actions performed on behalf of the authenticated MISP victim.

Affected Products

  • MISP versions prior to 2.5.47
  • MISP AnalystDataController component
  • MISP Overmind theme AnalystData thread element (app/View/Themed/Overmind/Elements/AnalystData/thread.ctp)

Discovery Timeline

  • 2026-09-22 - CVE-2026-95659 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95659

Vulnerability Analysis

The vulnerability exists in the AnalystDataController::viewForObject controller action within MISP. The action reads a parent object type parameter directly from the request URL and forwards it to the Overmind theme's AnalystData thread view element. Inside thread.ctp, the parameter is interpolated into two translated strings using PHP's __() function and rendered into the HTML response without invoking the h() output-encoding helper.

Exploitation requires an authenticated MISP session and user interaction, since the victim must navigate to the attacker-supplied URL. Once triggered, injected JavaScript executes with the origin and privileges of the MISP application. This permits reading session cookies, modifying rendered content, and issuing API requests as the victim. The scope is limited to reflected delivery, so no server-side state is altered by the payload itself.

Root Cause

The root cause is missing output encoding on user-controlled input flowing from the URL through the controller into a view template. The affected sink used the pattern __('No analyst data attached to this %s yet.', strtolower($objectType)), where $objectType originated from the request and was not sanitized before HTML rendering.

Attack Vector

Exploitation is network-based and requires low privileges plus active user interaction. An attacker with an authenticated MISP account crafts a URL targeting the viewForObject action with a malicious objectType value containing HTML or JavaScript. The attacker then delivers this URL via phishing, chat, or another MISP-hosted link. When the authenticated victim visits the URL, the payload reflects into the rendered page and executes.

php
// Security patch: app/View/Themed/Overmind/Elements/AnalystData/thread.ctp
<?php if ($total === 0): ?>
    <div class="text-center text-muted py-4">
        <i class="fas fa-comment-slash mb-2" style="font-size:1.5rem;"></i>
-       <div><?= __('No analyst data attached to this %s yet.', strtolower($objectType)) ?></div>
+       <div><?= __('No analyst data attached to this %s yet.', h(strtolower($objectType))) ?></div>
    </div>
<?php else: ?>
<div class="d-flex flex-column gap-4">

Source: GitHub MISP Commit 23b879073. The fix wraps the interpolated $objectType with the h() helper to HTML-encode special characters before rendering.

Detection Methods for CVE-2026-95659

Indicators of Compromise

  • Requests to MISP paths invoking AnalystDataController::viewForObject where the object type URL parameter contains <, >, ", ', or script tokens.
  • Web server or reverse-proxy logs showing referers from external domains preceding hits on the viewForObject endpoint.
  • Unusual outbound API calls from an authenticated MISP session immediately after a viewForObject request.

Detection Strategies

  • Deploy web application firewall (WAF) rules that inspect the object type URL parameter for HTML-encoded or raw script payloads.
  • Alert on MISP access logs where request URIs targeting AnalystDataController contain non-alphanumeric characters in the object type field.
  • Correlate authenticated MISP sessions that trigger the vulnerable endpoint with subsequent anomalous administrative or data-export actions.

Monitoring Recommendations

  • Enable verbose HTTP access logging on the MISP web tier and forward logs to a centralized analytics pipeline.
  • Monitor Content Security Policy (CSP) violation reports if CSP is enabled, since injected inline scripts should generate reports.
  • Track MISP application version drift across instances and alert when hosts remain below 2.5.47.

How to Mitigate CVE-2026-95659

Immediate Actions Required

  • Upgrade MISP to version 2.5.47 or later, which contains commit 23b879073 applying HTML encoding to the affected view.
  • Enforce a restrictive Content Security Policy that blocks inline script execution in the MISP application context.
  • Educate MISP users to avoid clicking untrusted URLs, since exploitation depends on user interaction.

Patch Information

The upstream fix is available in the MISP repository via commit 23b879073, which imports the AnalystData model and wraps the objectType interpolation with the h() output-encoding helper in app/View/Themed/Overmind/Elements/AnalystData/thread.ctp. See the GitHub MISP Commit 23b879073 for the full patch.

Workarounds

  • Temporarily switch away from the Overmind theme to a theme that does not include the vulnerable AnalystData thread element.
  • Restrict access to the AnalystDataController::viewForObject endpoint via reverse-proxy rules until the patch is applied.
  • Apply a WAF signature that rejects requests where the object type URL parameter contains HTML metacharacters.
bash
# Example nginx rule to block suspicious object type parameters on MISP
location ~ /analyst_data/viewForObject/ {
    if ($args ~* "(<|%3C|script|onerror|onload)") {
        return 403;
    }
    proxy_pass http://misp_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.