CVE-2026-39962: LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable

Published Apr 9, 2026
·
Updated

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTEUSER (such as in certain proxy setups). An attacker able to control that value can manipulate the LDAP search filter and potentially bypass authentication constraints or cause unauthorized LDAP queries. This vulnerability is fixed in 2.5.36.

Affected Software

2 affected components
Misp Project Misp<2.5.36
Misp-project Misp<2.5.36

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in 2.5.36
  2. Configuration

    Configure ApacheAuthenticate.apacheEnv to use REMOTE_USER instead of a user-controlled server variable (do not rely on proxy-supplied or other user-controlled server variables).

    MISP ApacheAuthenticate ApacheAuthenticate.apacheEnv = REMOTE_USER

Event History

Apr 9, 2026
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-39962?

CVE-2026-39962 is classified as a moderate severity vulnerability due to the potential for LDAP injection attacks.

2

How do I fix CVE-2026-39962?

To fix CVE-2026-39962, upgrade MISP to version 2.5.36 or later to mitigate the LDAP injection vulnerability.

3

What type of vulnerability is CVE-2026-39962?

CVE-2026-39962 is an LDAP injection vulnerability that can occur in the MISP ApacheAuthenticate component.

4

Which versions of MISP are affected by CVE-2026-39962?

CVE-2026-39962 affects MISP versions prior to 2.5.36.

5

How does CVE-2026-39962 exploit user-controlled input?

CVE-2026-39962 exploits user-controlled Apache environment variables to inject malicious queries into LDAP operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-39962 - LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable - SecAlerts