MISP security advisory (AV26-986)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-986Date: October 1, 2026 As of October 1, 2026, MISP is affected by vulnerabilities in the following product: MISP Prior to 2.5.48 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Delegation requests stay bound to the event they were authorised for A nested model alias key no longer selects the row a save targets Tag collection saves no longer write sibling user/org rows Refuse a TOTP code that was already used to log in Security Advisories and Reporting Security Vulnerabilities

This version

Version
1 of 1
Recorded
October 01, 2026 20:00
Change
Initial
Content hash
0d73dd163a5c55024fddd5defb48b3a2
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.