CVE-2026-95658

CVE-2026-95658 published: MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Becau...

View full NVD advisory → ← Back to CVE watch