CVE-2026-92003: Misp
Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - API requests with no authentication key; - requests supplying an API key with an incorrect length Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry. Version affected: ≤2.5.45
Affected products
- Misp Misp: before 2.5.46 (fixed in 2.5.46)
Published 2026-09-15. Last modified 2026-09-16.