Information Disclosure Vulnerability in MISP
An authenticated remote attacker can exploit a vulnerability in MISP to gain unauthorized access to sensitive information due to improper access controls.
CVE search metadata
CVE search record: CVE-2024-52293. Severity: high. CVSS: 7.2. EPSS: 1.36%. KEV: no. Product: MISP (< 4.12.2). Brief: Information Disclosure Vulnerability in MISP. Brief link: https://feed.craftedsignal.io/briefs/2026-09-misp-info-disclosure/
The MISP Project has disclosed a security vulnerability identified as CVE-2024-52293 affecting the Malware Information Sharing Platform (MISP). The vulnerability allows a remote, authenticated attacker to bypass intended access controls and access sensitive information within the platform. This issue impacts installations of MISP where insufficient authorization checks are performed on specific API endpoints or internal data structures. Because MISP is often used to store highly sensitive threat intelligence, unauthorized access to this data can lead to the exposure of proprietary intelligence, internal security configurations, and indicators of compromise. Organizations utilizing MISP should prioritize reviewing access logs for anomalous data access patterns and ensure their instances are updated to the latest security release addressing this vulnerability.
Impact
Successful exploitation results in the unauthorized disclosure of sensitive threat intelligence stored within the MISP platform. This can jeopardize the security operations of affected organizations, as threat actors could gain visibility into active defensive measures, investigation metadata, or sensitive indicator feeds. The severity is compounded by the centralized nature of MISP in intelligence-sharing ecosystems.
Recommendation
- Upgrade the MISP instance to the latest security version provided by the MISP Project that addresses CVE-2024-52293.
- Review internal MISP access logs for atypical user activity or excessive data export requests.
- Enforce the principle of least privilege for all user accounts accessing the MISP API and web interface.
Mitigations
Upgrade MISP to 4.12.2 or later
CVE-2024-52293