THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86452 (HIGH 7.5) — Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonab

[NVD] CVE-2026-86452 (HIGH 7.5) — Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonab

mednvdPublished 2026-09-07

CVE-2026-86452 CVSS: 7.5 HIGH Published: 2026-09-07T14:16:56.833

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting.

The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format. That value w

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86452