Threats Tagged 'cve-2026-77710'
View all threats tagged with 'cve-2026-77710'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-77710'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in misp-stix allows a crafted STIX document to manipulate security-sensitive MISP attribute metadata during import. The STIX import logic relied on untrusted document metadata to select the parser, enabling attackers to spoof MISP-origin indicators. This flaw permits injection of unauthorized attribute properties such as distribution and sharing restrictions, potentially violating organizational policies or affecting downstream processing. Join the discussion | GCVE Database | 08/21/2026, 09:32:06 UTC Added: 08/21/2026, 14:22:26 UTC |
CVE-2026-77710 is a medium severity vulnerability in the misp-stix component of MISP that allows crafted STIX documents to manipulate security-sensitive attribute metadata during import. The vulnerability arises because the parser selection for STIX documents is based on untrusted metadata controlled by the document producer, enabling attackers to spoof MISP-origin indicators. This leads to improper input validation where attacker-supplied STIX bundles can inject unauthorized attribute properties such as distribution, sharing restrictions, and tags. This can cause information to be shared against organizational policies or influence downstream processing. The issue is addressed by introducing an explicit classification parameter and restricting accepted attribute fields via an allow-list. Join the discussion | CVE Database V5 | 08/21/2026, 08:54:01 UTC Added: 08/21/2026, 09:08:12 UTC |
Showing 1 to 2 of 2 results