{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/misp-project/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2024-52293"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MISP (\u003c 4.12.2)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MISP Project"],"content_html":"\u003cp\u003eThe MISP Project has disclosed a security vulnerability identified as CVE-2024-52293 affecting the Malware Information Sharing Platform (MISP). The vulnerability allows a remote, authenticated attacker to bypass intended access controls and access sensitive information within the platform. This issue impacts installations of MISP where insufficient authorization checks are performed on specific API endpoints or internal data structures. Because MISP is often used to store highly sensitive threat intelligence, unauthorized access to this data can lead to the exposure of proprietary intelligence, internal security configurations, and indicators of compromise. Organizations utilizing MISP should prioritize reviewing access logs for anomalous data access patterns and ensure their instances are updated to the latest security release addressing this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of sensitive threat intelligence stored within the MISP platform. This can jeopardize the security operations of affected organizations, as threat actors could gain visibility into active defensive measures, investigation metadata, or sensitive indicator feeds. The severity is compounded by the centralized nature of MISP in intelligence-sharing ecosystems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the MISP instance to the latest security version provided by the MISP Project that addresses CVE-2024-52293.\u003c/li\u003e\n\u003cli\u003eReview internal MISP access logs for atypical user activity or excessive data export requests.\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege for all user accounts accessing the MISP API and web interface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T13:33:52Z","date_published":"2026-09-07T13:33:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-misp-info-disclosure/","summary":"An authenticated remote attacker can exploit a vulnerability in MISP to gain unauthorized access to sensitive information due to improper access controls.","title":"Information Disclosure Vulnerability in MISP","url":"https://feed.craftedsignal.io/briefs/2026-09-misp-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - MISP Project","version":"https://jsonfeed.org/version/1.1"}