CVE-2026-106513: MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration Change

Published Oct 6, 2026
·
Updated

MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the downloadattachmentsonload setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection.

Affected Software

1 affected component
Misp Misp

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Add the cli_only flag to MISP.redis_host, Plugin.ZeroMQ_redis_host, SimpleBackgroundJobs.redis_host, and download_attachments_on_load so these settings can be modified only through the server configuration file or CLI, not through the web UI or API.

    MISP cli_only for MISP.redis_host, Plugin.ZeroMQ_redis_host, SimpleBackgroundJobs.redis_host, and download_attachments_on_load = true

Event History

Oct 6, 2026
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need before exploitation is possible?

The attacker needs a compromised site-admin session or equivalent site-admin privileges. Unauthenticated access is not sufficient, and the described attack also requires a prior session-compromise mechanism.

2

Which systems or processes are at risk after the configuration is changed?

The affected Redis host settings cover the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin. Workers that connect to an attacker-controlled Redis instance may execute injected job payloads.

3

What level of access can exploitation provide?

Injected job payloads can result in arbitrary command execution in the context of the worker account. The attacker must change the Redis host settings and restart the workers before supplying the malicious payloads.

4

What configuration changes should be investigated after a suspected site-admin session compromise?

Review Redis host settings for the core application, ZeroMQ plugin, and SimpleBackgroundJobs plugin for changes that point to untrusted Redis servers. Also review whether download_attachments_on_load was re-enabled, and whether workers were restarted after those changes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203