MISP security advisory (AV26-946)
Canada's Cyber Centre warns MISP before 2.5.47 lets read-only API keys regain full privileges.
On September 21, 2026, the Canadian Centre for Cyber Security published advisory AV26-946 for MISP versions before 2.5.47. The issues include client identifiers leaking into module-result event reports, read-only API keys that can recover full role privileges, and export uploads whose content is a path or URL. The centre urges administrators to review the linked fixes and apply updates as they become available. No CVE identifiers or observed exploitation are stated.
- Advisory AV26-946 covers MISP versions before 2.5.47.
- Read-only API keys can regain full role powers.
- Export uploads that are a path or URL should be refused.
- Client IDs should be stripped from module-result event reports.
Full article76 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-946
Date: September 21, 2026
As of September 21, 2026, MISP is affected by vulnerabilities in the following product:
- MISP
- Prior to 2.5.47
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-946