CVE-2026-104906
Last modified
CVE-2026-104906 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding.
Description
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104906?
How severe is CVE-2026-104906?
How do I fix CVE-2026-104906?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104851fsspec is a specification and Python implementation framewor…8.8
- CVE-2026-104853Nx is a monorepo solution for TypeScript and polyglot codeba…5.8
- CVE-2026-104854Nx is a monorepo solution for TypeScript and polyglot codeba…8.5
- CVE-2026-1049A security vulnerability has been detected in LigeroSmart up…5.4
- CVE-2026-104900MISP contains a stored cross-site scripting (XSS) vulnerabil…5.3
- CVE-2026-104901MISP contains a cross-site scripting (XSS) vulnerability in …5.1
- CVE-2026-104907MISP contains a cross-site scripting (XSS) vulnerability in …4.8
- CVE-2026-104908MISP contains an improper input validation vulnerability in …7.1
- CVE-2026-104910MISP contains an authorization bypass in the related events …5.3
- CVE-2026-104912MISP contains an authorization flaw in its correlation handl…7.1
- CVE-2026-104914MISP contains an improper access control vulnerability in it…5.3
- CVE-2026-1050A flaw has been found in risesoft-y9 Digital-Infrastructure …7.3
Are you affected by CVE-2026-104906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
