{"id":"CVE-2026-95701","published":"2026-09-22T15:17:28.103","lastModified":"2026-09-22T16:18:23.783","description":"In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path constructed as APP . 'webroot' . DS . 'img' . DS . 'orgs' . DS . $k . '.png', where $k is the organization name. Because the referenced directory (app/webroot/img/orgs) no longer exists in current MISP deployments (org logos were relocated to files/img/orgs), the check was functionally dead and never triggered. However, the underlying pattern—concatenating an attacker-influenced organization name into a file path without sanitization—constitutes a path traversal weakness. An organization name containing directory traversal sequences (e.g., '../../../../etc/passwd') would, if the target directory existed, allow an authenticated user with the ability to create or rename an organization to probe for the existence of arbitrary files on the server.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://github.com/MISP/MISP/commit/a2f7cba6e","tags":[]}],"exploitRefs":[{"url":"https://github.com/MISP/MISP/commit/a2f7cba6e","tags":[]}],"hasPoc":true,"ai":null}