CVE-2026-95682 Overview
CVE-2026-95682 is a stored cross-site scripting (XSS) vulnerability in MISP, the open-source threat intelligence platform. The flaw resides in the admin email composition screen, where the MISP.org organization name setting is interpolated directly into a JavaScript string literal without output encoding. An administrator who can set or modify the organization name can inject arbitrary JavaScript that executes when another authenticated user loads the affected admin view. The vulnerability is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).
Critical Impact
Successful exploitation allows an attacker with administrative privileges to execute JavaScript in the browser session of any authenticated user visiting the admin email page, enabling session hijacking, data exfiltration, or privileged actions on behalf of the victim.
Affected Products
- MISP (Malware Information Sharing Platform) prior to the commit 5d6ace65e
- Instances where the MISP.org configuration value can be modified by an authenticated administrator
- Any MISP deployment rendering the admin email composition view (app/View/Users/admin_email.ctp)
Discovery Timeline
- 2026-09-22 - CVE-2026-95682 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-95682
Vulnerability Analysis
The vulnerability exists in the MISP admin email composition template app/View/Users/admin_email.ctp. The template renders the organization name into a JavaScript context using a raw PHP echo:
var org = "<?php echo $org;?>";
Because the value is placed inside a double-quoted JavaScript string with no escaping, an organization name containing a double-quote or backslash character terminates the string literal. The remaining characters are parsed as JavaScript. This is a classic case of insufficient output encoding when data crosses from a server-side context into a client-side scripting context.
The injected payload executes in the browser of any authenticated user who loads the admin email page. Because MISP administrators routinely interact with this view for user onboarding and password reset workflows, the payload runs with the victim's privileges. That enables session token theft, forced privileged API calls, and exfiltration of threat intelligence data accessible to the victim.
Root Cause
The root cause is missing context-aware output encoding. Server-side data was written into a JavaScript string literal without JSON encoding or JavaScript escaping. Neither HTML escaping nor input validation is sufficient for this context; the value must be encoded specifically for embedding in JavaScript.
Attack Vector
Exploitation requires two conditions. First, an authenticated attacker with the ability to set or modify the MISP.org organization name setting stores a payload such as "; <malicious_js>; //. Second, another authenticated user loads the admin email view, causing the injected script to execute in that user's session context.
var standardTexts = [];
var submitAllowed = false;
$(document).ready(function() {
- var org = "<?php echo $org;?>";
+ var org = <?php echo json_encode($org, JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT); ?>;
subjects = ["", "[" + org + " MISP] " + "<?php echo __('New user registration');?>" , "[" + org + " MISP] " + "<?php echo __('Password reset');?>"];
standardTexts = ['', '<?php echo h($newUserText); ?>', '<?php echo h($passwordResetText); ?>'];
setAll();
Source: MISP commit 5d6ace65e — the patch replaces the unescaped echo with json_encode using JSON_HEX_TAG, JSON_HEX_AMP, JSON_HEX_APOS, and JSON_HEX_QUOT flags, producing a safe JavaScript literal regardless of the input value.
Detection Methods for CVE-2026-95682
Indicators of Compromise
- Unexpected characters such as ", \, <, or > present in the MISP.org configuration value stored in the MISP database or configuration file.
- Audit log entries showing modifications to the organization name setting by non-standard or recently escalated administrator accounts.
- Browser console errors or unexpected outbound requests originating from admin sessions that loaded /users/admin_email.
Detection Strategies
- Inspect the current MISP.org value and any historical revisions for payloads containing quote characters, HTML tags, or JavaScript keywords.
- Review MISP audit logs for administrative changes to organization settings, correlating with subsequent visits to the admin email view.
- Deploy web application firewall rules that flag responses from /users/admin_email containing unescaped script fragments within JavaScript string literals.
Monitoring Recommendations
- Monitor authenticated administrator sessions for anomalous API activity following visits to the admin email composition page.
- Alert on configuration changes to sensitive MISP settings, particularly MISP.org, and require secondary review.
- Track outbound HTTP requests from browsers used to administer MISP for beaconing to unfamiliar domains that could indicate token exfiltration.
How to Mitigate CVE-2026-95682
Immediate Actions Required
- Apply the upstream MISP patch from commit 5d6ace65e or upgrade to the first tagged release that includes the fix.
- Review the current MISP.org value and remove any characters that could break out of a JavaScript string literal.
- Audit administrative accounts and revoke unused or over-privileged roles that could set the organization name.
Patch Information
The fix is implemented in app/View/Users/admin_email.ctp and replaces the unsafe echo with json_encode($org, JSON_HEX_TAG | JSON_HEX_AMP | JSON_HEX_APOS | JSON_HEX_QUOT). This produces a JavaScript-safe literal for any input. Full details are available in the MISP GitHub commit.
Workarounds
- Until the patch can be applied, restrict who can modify the MISP.org setting to a small set of trusted administrators.
- Manually sanitize the organization name to contain only alphanumeric characters, spaces, hyphens, and underscores.
- Enforce a Content Security Policy (CSP) that disallows inline scripts to reduce the impact of stored XSS payloads.
# Apply the upstream fix to an existing MISP checkout
cd /var/www/MISP
sudo -u www-data git fetch origin
sudo -u www-data git cherry-pick 5d6ace65e
# Verify the patched line in the template
grep -n 'json_encode($org' app/View/Users/admin_email.ctp
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
