CVE-2026-56446

Severity CVSS v4.0:
HIGH
Type:
CWE-94 Code Injection
Publication date:
22/06/2026
Last modified:
23/06/2026

Description

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP file in a web-accessible directory and inject PHP code through logged data. Accessing the resulting file could lead to remote code execution with the privileges of the web server process.<br /> <br /> The fix restricts log destinations to existing directories beneath APP/tmp/logs or /var/log, requires absolute paths, rejects stream wrappers and traversal-related input, and limits filenames to .log or .ndjson extensions while disallowing executable extension segments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:* 2.5.42 (excluding)