Serial number: AV26-986
Date: October 1, 2026
As of October 1, 2026, MISP is affected by vulnerabilities in the following product:
- MISP
- Prior to 2.5.48
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Delegation requests stay bound to the event they were authorised for
- A nested model alias key no longer selects the row a save targets
- Tag collection saves no longer write sibling user/org rows
- Refuse a TOTP code that was already used to log in
- Security Advisories and Reporting Security Vulnerabilities