Visibility Control Issue in MISP Affecting Non-Site-Admin Users
CVE-2026-10854
5.3MEDIUM
What is CVE-2026-10854?
A visibility control issue in the event template creation workflow of MISP allowed non-site-admin users to access private galaxies owned by other organizations. This flaw occurred when the event template builder loaded all enabled galaxies without applying proper organization or distribution-based access restrictions, resulting in unauthorized exposure of sensitive galaxy metadata, including type and description. The vulnerability has been addressed by ensuring that non-site-admin users can only query galaxies owned by their organization or those with a non-private distribution setting, maintaining overall security for site administrators who still have visibility over all enabled galaxies.
Affected Version(s)
misp 0 <= 2.5.38
