Skip to main content

Threats Tagged 'cve-2026-77710'

View all threats tagged with 'cve-2026-77710'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-77710

Threats Tagged 'cve-2026-77710'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in misp-stix allows a crafted STIX document to manipulate security-sensitive MISP attribute metadata during import. The STIX import logic relied on untrusted document metadata to select the parser, enabling attackers to spoof MISP-origin indicators. This flaw permits injection of unauthorized attribute properties such as distribution and sharing restrictions, potentially violating organizational policies or affecting downstream processing.

Join the discussion

CVE-2026-77710 is a medium severity vulnerability in the misp-stix component of MISP that allows crafted STIX documents to manipulate security-sensitive attribute metadata during import. The vulnerability arises because the parser selection for STIX documents is based on untrusted metadata controlled by the document producer, enabling attackers to spoof MISP-origin indicators. This leads to improper input validation where attacker-supplied STIX bundles can inject unauthorized attribute properties such as distribution, sharing restrictions, and tags. This can cause information to be shared against organizational policies or influence downstream processing. The issue is addressed by introducing an explicit classification parameter and restricting accepted attribute fields via an allow-list.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-77710
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses