ctipilot.ch
← Back to Daily brief 2026-06-25
HIGHCVE-2026-56447 +5vulnerability

CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422 — MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening

discovered 2026-06-25 04:59 UTCrun 2026-06-25-da7fbd233 sourcesmulti-source

MISP 2.5.42 (released 2026-06-22 by the CIRCL-supported project) is a security-hardening release listing six CVEs in the threat-intelligence platform that most EU national CERTs/CSIRTs run (MISP, 2026-06-22 · GitHub release v2.5.42). The release fixes two remote-code-execution paths: CVE-2026-56447 (CVSS 9.3 per the GitHub advisory) lets a site administrator point Kafka_rdkafka_config at a crafted file that abuses rdkafka's plugin.library.paths to load an attacker-supplied shared library under MISP's process privileges (GHSA-834x-pvxg-xh58); a second RCE comes from arbitrary NDJSON-log paths, now strictly controlled in 2.5.42 (T1505.003). Both require a site-admin account, so the practical risk is post-compromise persistence/lateral movement on a shared instance. The remaining fixes harden Azure-AD authentication and close broken-access-control / mass-assignment issues across MISP's controllers (CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422); the release notes do not publish per-CVE CVSS scores. A compromised MISP instance exposes a whole community's TLP:AMBER/RED corpus and can be used to inject false indicators — upgrade to 2.5.42, verify file ownership on APP/tmp/ and the web root, and audit the admin trail for Kafka/log-path changes.

A malicious configuration file could exploit rdkafka's plugin.library.paths feature to load external libraries, enabling arbitrary code execution under MISP's process privileges.

GitHub Security Advisory GHSA-834x-pvxg-xh58

RCE via arbitrary ndjson log paths — the ndjson log file path/name is now strictly controlled.

MISP 2.5.42 release notes

Defender actions

  • Upgrade MISP to 2.5.42 now if you run a MISP instance — six CVEs including two site-admin RCE paths (rdkafka plugin-load CVE-2026-56447, CVSS 9.3; and an ndjson log-path RCE). Verify file ownership on APP/tmp/ and the web root and audit the admin trail for Kafka/log-path changes. ()

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.