THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85236 — A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an

[NVD] CVE-2026-85236 — A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an

mednvdPublished 2026-09-03

CVE-2026-85236 CVSS: None Published: 2026-09-03T16:18:27.013

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests.

Because bodyless GET requests are not subject to CakePHP's CSRF validation, an attacker could cause an authenticated MISP user with suff

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85236