PT-2026-31660 · Misp+1 · Misp+1

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2026-39962

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.36
Description MISP is a threat intelligence and sharing platform. A flaw exists in the LDAP query handling within ApacheAuthenticate.php, specifically due to improper neutralization of special elements. This allows for LDAP injection via manipulation of the username value when ApacheAuthenticate.apacheEnv is configured to utilize a user-controlled server variable instead of REMOTE USER. An attacker controlling this variable can modify the LDAP search filter, potentially bypassing authentication or executing unauthorized LDAP queries.
Recommendations Update to version 2.5.36 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-39962

Affected Products

Apache
Misp