CVE-2026-94379

CVE-2026-94379 published: The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing ...

View full NVD advisory → ← Back to CVE watch