PT-2026-38424 · Misp · Misp

Bjørn Helseth

+1

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-8080

CVSS v4.0

6.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Green
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.37
Description A stored cross-site scripting issue exists in the template element attribute handling logic. The application fails to validate arbitrary values for the TemplateElementAttribute type and category fields against known attribute type and category definitions. This allows an attacker with permissions to create or modify template element attributes to store a crafted type value. This issue specifically affects the old templating engine, which is no longer accessible in version 2.5.37 and is scheduled for removal in version 2.5.38.
Recommendations Update to version 2.5.37 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8080

Affected Products

Misp