---
schema: 1
kind: vulnerability
title: "CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422 — MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening"
headline: "CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422 — MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and"
summary: "Patch your own tooling — MISP 2.5.42 closes six CVEs including two site-admin RCE paths (rdkafka plugin-load and ndjson log injection) plus Azure-AD auth and access-control hardening, directly affecting the threat-intel platform most EU CERTs/CSIRTs run (MISP, 2026-06-22)."
discovered_at: "2026-06-25T04:59:07Z"
event_date: 2026-06-22
run_id: 2026-06-25-da7fbd23
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - identity
  - patch-available
  - eu-nexus
regions:
  - europe
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-56447
    cvss: "9.3"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-56446
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-56425
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-56424
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-56423
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-56422
    cvss: n/a
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://www.misp-project.org/2026/06/22/misp.2.5.42.release.html/"
    publisher: MISP 2.5.42 release notes
    role: primary
  - url: "https://github.com/MISP/MISP/releases/tag/v2.5.42"
    publisher: GitHub release v2.5.42
    role: corroborating
  - url: "https://github.com/advisories/GHSA-834x-pvxg-xh58"
    publisher: GitHub Security Advisory GHSA-834x-pvxg-xh58
    role: corroborating
closed_sources: []
evidence:
  - quote: "A malicious configuration file could exploit rdkafka's plugin.library.paths feature to load external libraries, enabling arbitrary code execution under MISP's process privileges."
    publisher: GitHub Security Advisory GHSA-834x-pvxg-xh58
  - quote: RCE via arbitrary ndjson log paths — the ndjson log file path/name is now strictly controlled.
    publisher: MISP 2.5.42 release notes
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Upgrade MISP to 2.5.42 now** if you run a MISP instance — six CVEs including two site-admin RCE paths (rdkafka plugin-load CVE-2026-56447, CVSS 9.3; and an ndjson log-path RCE). Verify file ownership on `APP/tmp/` and the web root and audit the admin trail for Kafka/log-path changes. ()"
migrated_from: briefs/2026-06-25.md
---

MISP 2.5.42 (released 2026-06-22 by the CIRCL-supported project) is a security-hardening release listing six CVEs in the threat-intelligence platform that most EU national CERTs/CSIRTs run ([MISP, 2026-06-22](https://www.misp-project.org/2026/06/22/misp.2.5.42.release.html/) · [GitHub release v2.5.42](https://github.com/MISP/MISP/releases/tag/v2.5.42)). The release fixes two remote-code-execution paths: CVE-2026-56447 (CVSS 9.3 per the GitHub advisory) lets a site administrator point `Kafka_rdkafka_config` at a crafted file that abuses rdkafka's `plugin.library.paths` to load an attacker-supplied shared library under MISP's process privileges ([GHSA-834x-pvxg-xh58](https://github.com/advisories/GHSA-834x-pvxg-xh58)); a second RCE comes from arbitrary NDJSON-log paths, now strictly controlled in 2.5.42 (`T1505.003`). Both require a site-admin account, so the practical risk is post-compromise persistence/lateral movement on a shared instance. The remaining fixes harden Azure-AD authentication and close broken-access-control / mass-assignment issues across MISP's controllers (CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422); the release notes do not publish per-CVE CVSS scores. A compromised MISP instance exposes a whole community's TLP:AMBER/RED corpus and can be used to inject false indicators — upgrade to 2.5.42, verify file ownership on `APP/tmp/` and the web root, and audit the admin trail for Kafka/log-path changes.
