CVE-2026-92003: Misp

Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests supplying an API key with an incorrect length Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry. Version affected: ≤2.5.45

Affected products

  • Misp Misp: before 2.5.46 (fixed in 2.5.46)

Published 2026-09-15. Last modified 2026-09-16.