{"id":"CVE-2026-95703","published":"2026-09-22T15:17:28.323","lastModified":"2026-09-22T16:18:23.977","description":"In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is_uploaded_file. An authenticated site-admin user could supply an arbitrary server file path as the tmp_name parameter. The application would then probe that path and return distinct validation error messages depending on whether the file existed and what its image type was, effectively creating a file-existence and image-type oracle against the server filesystem.\n\nThe vulnerability requires site-admin privileges and does not allow arbitrary file read, code execution, or modification; the impact is limited to disclosure of whether a given path exists on the server and, for image files, their type.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-20","CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://github.com/MISP/MISP/commit/12eaadc9e","tags":[]}],"exploitRefs":[{"url":"https://github.com/MISP/MISP/commit/12eaadc9e","tags":[]}],"hasPoc":true,"ai":null}