Skip to main content
QUIETLYTIC
Vulnerability

MISP Open Redirect (CVE-2026-86351)

CVE-2026-86351 is a CVSS 6.1 medium-severity open-redirect vulnerability in MISP, the widely used threat-intelligence sharing platform, via a protocol-relative homepage URL bypassing validation.

CVE-2026-86351
Threat Level
MEDIUM
CVSS
6.1
Status
Monitored
Confidence
High
Affected Products
MISP

CVE-2026-86351 is a medium-severity (CVSS 3.1 base 6.1) open-redirect vulnerability in MISP, the open-source threat-intelligence sharing platform used across the CTI community — notably including the same MITRE ATT&CK-adjacent ecosystem this site’s own threat-actor and malware profiles draw on.

What the vulnerability does

Per the project’s own commit description, affected versions validate a user-configurable homepage setting by checking only whether the supplied path begins with /. That check is insufficient: a protocol-relative URL such as //attacker.example also begins with /, but browsers resolve it to an external origin rather than treating it as a same-site path. The vulnerable homepage value can be stored as a user setting and is later used by MISP’s post-login routing logic — the project’s own fix commit explicitly identifies //attacker.example as a payload that passed the old validation and was emitted to the Location header after a successful login.

Affected versions: ≤2.5.45.

Fix

MISP’s fix introduces a shared InternalRedirectValidator that rejects URLs containing a host, scheme, userinfo, an unsafe leading // or /\, malformed URLs, and control characters. It also revalidates homepage settings on read, so a legacy or internally-written unsafe value already stored before the fix can’t bypass the new storage-time validation retroactively.

Confidence

This record traces directly to MISP’s own GitHub repository and fix commit, describing both the vulnerable logic and the exact bypass payload — confidence is high.

Why this matters

An open redirect triggered immediately after a successful login is a phishing-adjacent primitive: a link to the real, trusted MISP instance that silently redirects to an attacker-controlled page after authentication can be used to harvest credentials in a follow-on phishing step, or to chain into other attacks that rely on an initial trusted-looking URL. Given MISP’s role as shared threat-intelligence infrastructure across security teams, organizations running a self-hosted MISP instance at or below 2.5.45 should upgrade promptly.

Frequently Asked Questions

What is CVE-2026-86351? A CVSS 6.1 medium-severity open-redirect vulnerability in MISP (versions ≤2.5.45), where a protocol-relative homepage URL like //attacker.example bypasses validation and is used in post-login redirect logic.

Which version fixes CVE-2026-86351? Any version incorporating MISP’s InternalRedirectValidator fix, released after the vulnerability was patched — check MISP’s own release notes for the specific version.

Is CVE-2026-86351 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from MISP’s own GitHub repository and the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 MISP (GitHub)
02 National Vulnerability Database (NVD)

Related intelligence


Analyst tools