Affected versions of MISP expose several state-changing controller actions without restricting them to POST.
The affected actions are:
- EventReportsController::purgeUnusedPictures()
- NoticelistsController::enableNoticelist()
- ServersController::removeOrphanedCorrelations()
- WorkflowsController::rebuildRedis()
The patch adds allowMethod(['post']) to each action, preventing them from being triggered through ordinary GET requests.
For purgeUnusedPictures(), the corresponding UI previously used $.get(). The fix converts that request to POST and supplies X-CSRF-Token, while the controller enables header-only CSRF validation for that AJAX action.
Because GET requests can be induced cross-origin through links, images, redirects, or navigation, accepting GET for these state-changing operations can let an attacker trigger them using the authenticated victim's session.
Version affected: ≤2.5.45
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/b4a5486b5 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 10:17
Updated : 2026-09-15 14:17
NVD link : CVE-2026-91857
Mitre link : CVE-2026-91857
CVE.ORG link : CVE-2026-91857
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
