PT-2026-40809 · Misp · Misp

CVE-2026-44381

·

Published

2026-05-13

·

Updated

2026-05-13

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.37
Description An issue exists in the handling of user-controlled ordering parameters within the event and shadow attribute listing endpoints. The software accepts order or sort values from request parameters and incorporates them into database query ordering clauses without sufficient validation of the requested field name. This allows an attacker to craft a malicious ordering parameter to manipulate the generated SQL query, which could lead to unauthorized data access or modification of query behavior depending on database permissions.
Recommendations Update to version 2.5.37.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44381
GHSA-4CXP-22WM-J6JR

Affected Products

Misp