CVE-2026-56447: MISP remote code execution via arbitrary rdkafka configuration path

Published Jun 22, 2026
·
Updated

MISP allowed an authenticated site administrator to set the Kafkardkafkaconfig setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka options such as plugin.library.paths to load an external library, resulting in arbitrary code execution with the privileges of the MISP process. An attacker could leverage a MISP-writable location, such as an uploaded file or administrative image, to host the malicious configuration file.

The issue is fixed by restricting the setting to absolute .ini files located only in approved configuration directories outside the webroot and MISP upload targets.

Affected Software

2 affected components
Misp Project Misp
Misp-project Misp<2.5.42

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict the Kafka_rdkafka_config setting so it only accepts absolute filesystem paths to .ini files located in approved configuration directories that are outside the webroot and any MISP-writable upload or administrative image locations.

    MISP Kafka_rdkafka_config = absolute path to a .ini file located only in approved configuration directories outside the webroot and MISP upload targets
  2. Compensating control

    Ensure MISP-writable locations (upload directories, administrative image directories, etc.) cannot be used to host configuration files: remove write permissions where not required, block uploads of .ini files, and ensure those directories are isolated from approved configuration directories so rdkafka cannot load libraries from them.

  3. Operational

    Audit current Kafka_rdkafka_config values and any referenced INI files; verify each referenced .ini is an absolute path located in an approved configuration directory outside the webroot and MISP upload targets. Remove or relocate any unapproved or suspicious INI files and update the setting to point only to approved files.

Event History

Jun 22, 2026
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-56447?

The severity of CVE-2026-56447 is rated at 66, indicating a moderate risk level.

2

How do I fix CVE-2026-56447?

To fix CVE-2026-56447, ensure that only trusted site administrators can configure the Kafka_rdkafka_config setting and validate file paths for configuration files.

3

What type of vulnerability is CVE-2026-56447?

CVE-2026-56447 is a remote code execution vulnerability due to unsecured configuration path settings in MISP.

4

Who is affected by CVE-2026-56447?

Authenticated site administrators using MISP are potentially at risk from CVE-2026-56447 if proper access controls are not enforced.

5

How does CVE-2026-56447 allow remote code execution?

CVE-2026-56447 allows remote code execution by enabling an administrator to specify an arbitrary filesystem path for configuration, which can then be manipulated by an attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203