Skip to main content
EPSS 0.3%top 78%

CVE-2026-97863: CWE-78 Improper Neutralization of Special Elements used in a Command ("Command Injection") in misp misp-modules

0
Medium
VulnerabilityCVE-2026-97863cvecve-2026-97863cwe-78
Published: 09/25/2026 (09/25/2026, 08:03:24 UTC)
Source: CVE Database V5
Vendor/Project: misp
Product: misp-modules

Description

The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event info comments) directly into single-quoted shell string assignments without any escaping or sanitization. Because the values are placed inside single-quoted shell strings, any value containing a single-quote character (e.g., a crafted ip-dst or url attribute value submitted to MISP) breaks out of the quoting context, allowing an attacker to inject arbitrary shell commands into the exported script. A security analyst who subsequently executes the generated .sh file unmodified would run the injected commands with their own privileges, potentially exposing fireSIGHT Manager credentials, modifying ACL rules, or compromising the analyst workstation. Additionally, the module contained a secondary defect where the variable 'config' was only assigned inside a conditional block but referenced unconditionally afterward, causing a NameError (denial of service) when the request payload lacked a 'config' key. The vulnerability requires the attacker to have the ability to submit MISP events or attributes containing a single-quote character and the victim to execute the exported script. No authentication bypass is required beyond standard MISP event-submission privileges.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
Active
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

Affected software

misp

misp-modules

Affected versions
>=0 <=3.0.10
GitHub Actionsmore threats →cve
misp-modules
pkg:github/misp-modules
Affected versions
>=0 <=3.0.10

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 08:47:39 UTC

Technical Analysis

The cisco_firesight_manager_ACL_rule_export module in misp-modules constructs a shell script by interpolating configuration and MISP attribute values directly into single-quoted shell string assignments without escaping or sanitization. If an attacker submits MISP attributes containing single-quote characters, they can break out of the quoting context and inject arbitrary shell commands into the exported script. When a security analyst executes this script, the injected commands run with their privileges, potentially compromising credentials, modifying ACL rules, or the analyst's workstation. A secondary issue is a NameError caused by referencing an unassigned variable 'config' when the request payload lacks a 'config' key, resulting in denial of service. Exploitation requires the ability to submit MISP events or attributes and the victim executing the exported script. No authentication bypass beyond standard MISP submission privileges is needed.

Potential Impact

Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the security analyst who runs the exported script. This can lead to exposure of Cisco fireSIGHT Manager credentials, unauthorized modification of ACL rules, or compromise of the analyst's workstation. The secondary defect can cause a denial of service by triggering a NameError when the 'config' key is missing in the request payload.

Mitigation Recommendations

No official patch or remediation is currently confirmed. Users should avoid executing exported shell scripts generated by the vulnerable module without first reviewing and sanitizing their contents. Restrict MISP event and attribute submission privileges to trusted users to reduce the risk of malicious input. Monitor vendor advisories for updates or patches addressing this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CIRCL
Date Reserved
2026-09-25T08:02:32.714Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab631d7f7a7c541068c0c97

Added to database: 09/25/2026, 08:33:27 UTC

Last enriched: 09/25/2026, 08:47:39 UTC

Last updated: 09/26/2026, 02:49:27 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses