CVE-2026-97863: CWE-78 Improper Neutralization of Special Elements used in a Command ("Command Injection") in misp misp-modules
The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event info comments) directly into single-quoted shell string assignments without any escaping or sanitization. Because the values are placed inside single-quoted shell strings, any value containing a single-quote character (e.g., a crafted ip-dst or url attribute value submitted to MISP) breaks out of the quoting context, allowing an attacker to inject arbitrary shell commands into the exported script. A security analyst who subsequently executes the generated .sh file unmodified would run the injected commands with their own privileges, potentially exposing fireSIGHT Manager credentials, modifying ACL rules, or compromising the analyst workstation. Additionally, the module contained a secondary defect where the variable 'config' was only assigned inside a conditional block but referenced unconditionally afterward, causing a NameError (denial of service) when the request payload lacked a 'config' key. The vulnerability requires the attacker to have the ability to submit MISP events or attributes containing a single-quote character and the victim to execute the exported script. No authentication bypass is required beyond standard MISP event-submission privileges.
AI Analysis
Technical Summary
The cisco_firesight_manager_ACL_rule_export module in misp-modules constructs a shell script by interpolating configuration and MISP attribute values directly into single-quoted shell string assignments without escaping or sanitization. If an attacker submits MISP attributes containing single-quote characters, they can break out of the quoting context and inject arbitrary shell commands into the exported script. When a security analyst executes this script, the injected commands run with their privileges, potentially compromising credentials, modifying ACL rules, or the analyst's workstation. A secondary issue is a NameError caused by referencing an unassigned variable 'config' when the request payload lacks a 'config' key, resulting in denial of service. Exploitation requires the ability to submit MISP events or attributes and the victim executing the exported script. No authentication bypass beyond standard MISP submission privileges is needed.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the security analyst who runs the exported script. This can lead to exposure of Cisco fireSIGHT Manager credentials, unauthorized modification of ACL rules, or compromise of the analyst's workstation. The secondary defect can cause a denial of service by triggering a NameError when the 'config' key is missing in the request payload.
Mitigation Recommendations
No official patch or remediation is currently confirmed. Users should avoid executing exported shell scripts generated by the vulnerable module without first reviewing and sanitizing their contents. Restrict MISP event and attribute submission privileges to trusted users to reduce the risk of malicious input. Monitor vendor advisories for updates or patches addressing this vulnerability.
CVE-2026-97863: CWE-78 Improper Neutralization of Special Elements used in a Command ("Command Injection") in misp misp-modules
Description
The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event info comments) directly into single-quoted shell string assignments without any escaping or sanitization. Because the values are placed inside single-quoted shell strings, any value containing a single-quote character (e.g., a crafted ip-dst or url attribute value submitted to MISP) breaks out of the quoting context, allowing an attacker to inject arbitrary shell commands into the exported script. A security analyst who subsequently executes the generated .sh file unmodified would run the injected commands with their own privileges, potentially exposing fireSIGHT Manager credentials, modifying ACL rules, or compromising the analyst workstation. Additionally, the module contained a secondary defect where the variable 'config' was only assigned inside a conditional block but referenced unconditionally afterward, causing a NameError (denial of service) when the request payload lacked a 'config' key. The vulnerability requires the attacker to have the ability to submit MISP events or attributes containing a single-quote character and the victim to execute the exported script. No authentication bypass is required beyond standard MISP event-submission privileges.
CVSS v4.0
Score 6.3medium
Affected software
misp
misp-modules
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The cisco_firesight_manager_ACL_rule_export module in misp-modules constructs a shell script by interpolating configuration and MISP attribute values directly into single-quoted shell string assignments without escaping or sanitization. If an attacker submits MISP attributes containing single-quote characters, they can break out of the quoting context and inject arbitrary shell commands into the exported script. When a security analyst executes this script, the injected commands run with their privileges, potentially compromising credentials, modifying ACL rules, or the analyst's workstation. A secondary issue is a NameError caused by referencing an unassigned variable 'config' when the request payload lacks a 'config' key, resulting in denial of service. Exploitation requires the ability to submit MISP events or attributes and the victim executing the exported script. No authentication bypass beyond standard MISP submission privileges is needed.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary shell commands with the privileges of the security analyst who runs the exported script. This can lead to exposure of Cisco fireSIGHT Manager credentials, unauthorized modification of ACL rules, or compromise of the analyst's workstation. The secondary defect can cause a denial of service by triggering a NameError when the 'config' key is missing in the request payload.
Mitigation Recommendations
No official patch or remediation is currently confirmed. Users should avoid executing exported shell scripts generated by the vulnerable module without first reviewing and sanitizing their contents. Restrict MISP event and attribute submission privileges to trusted users to reduce the risk of malicious input. Monitor vendor advisories for updates or patches addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-09-25T08:02:32.714Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab631d7f7a7c541068c0c97
Added to database: 09/25/2026, 08:33:27 UTC
Last enriched: 09/25/2026, 08:47:39 UTC
Last updated: 09/26/2026, 02:49:27 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.