# MISP 2.5.47 patches critical RCE and access-control flaws

Published: 2026-09-17 · Severity: routine
Canonical: https://vorant.io/reports/c9a10882-4590-554e-9e19-6bf05de54ad5/misp-2-5-47-patches-critical-rce-and-access-control-flaws

> MISP 2.5.47 closes 27 confirmed vulnerabilities including authenticated RCE, access-control bypasses, XSS, CSRF, and MFA bypass; update strongly recommended.

MISP 2.5.47 is a security-focused release addressing the outcome of an intensive external security review. Twenty-seven confirmed vulnerabilities were identified and fixed across multiple attack vectors: stored and reflected XSS in statistics, index and modal views; access-control bypasses in event reports, collections, sharing groups and distribution checks; CSRF exemptions on sensitive actions; a read-only API key that regained full account privileges; MFA and brute-force protection bypass via alternative HTTP verb on login; SSRF and local file read through XML parsing in MISP export uploads; path traversal in organisation logo handling; and most critically, unauthenticated remote code execution through background job argument handling accessible to any authenticated user. The release also introduced a new ledger-based database migration system replacing the legacy db_version counter, fresh PostgreSQL support as an alternative to MySQL/MariaDB, AI-assisted analysis integration for event summarisation and indicator extraction, and numerous Overmind interface improvements. Critical fixes include regression patches for background job stderr handling and CSRF validation introduced in 2.5.46.

Source reporting: https://www.misp-project.org/2026/09/17/misp.2.5.47.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c9a10882-4590-554e-9e19-6bf05de54ad5/misp-2-5-47-patches-critical-rce-and-access-control-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
