CVE-2026-95701: MISP Path Traversal via Organization Name in Org-Statistics Logo Check
In MISP, the statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called fileexists() with a path constructed as APP . 'webroot' . DS . 'img' . DS . 'orgs' . DS . $k . '.png', where $k is the organization name. Because the referenced directory (app/webroot/img/orgs) no longer exists in current MISP deployments (org logos were relocated to files/img/orgs), the check was functionally dead and never triggered. However, the underlying pattern—concatenating an attacker-influenced organization name into a file path without sanitization—constitutes a path traversal weakness. An organization name containing directory traversal sequences (e.g., '../../../../etc/passwd') would, if the target directory existed, allow an authenticated user with the ability to create or rename an organization to probe for the existence of arbitrary files on the server.
Affected Software
Event History
Frequently Asked Questions
Are current MISP deployments practically exposed to file-existence probing through this code path?
The described logo check targets app/webroot/img/orgs, a directory that no longer exists in current MISP deployments because organization logos were moved to files/img/orgs. As a result, the check is functionally dead and does not trigger in those deployments.
What access would an attacker need if the affected directory were present?
An attacker would need to be authenticated and able to create or rename an organization. They could then use traversal sequences in an organization name to probe whether arbitrary server-side files exist.
What is the impact described for exploitation?
The described behavior permits probing for the existence of arbitrary files, rather than reading their contents or modifying them. It relies on the organization name being incorporated into the file-system path without sanitization.