<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:16:06.242510+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367784</id>
    <title>EUVD-2026-367784</title>
    <updated>2026-10-07T10:16:06.294124+00:00</updated>
    <content>EUVD-2026-367784</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-90955</id>
    <title>fkie_cve-2026-90955</title>
    <updated>2026-10-07T10:16:06.294166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging.</p>
<p>The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user.</p>
<p>Version affected: ≤2.5.45</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-90955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wxf7-wrjx-26cc</id>
    <title>GHSA-wxf7-wrjx-26cc</title>
    <updated>2026-10-07T10:16:06.294210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging.</p>
<p>The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user.</p>
<p>Version affected: ≤2.5.45</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wxf7-wrjx-26cc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3370</id>
    <title>WID-SEC-W-2026-3370 — MISP: Mehrere Schwachstellen</title>
    <updated>2026-10-07T10:16:06.294233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und offenzulegen, beliebigen Code auszuführen und Benutzer auf bösartige URLs umzuleiten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3370"/>
  </entry>
</feed>
