Visibility Control Issue in MISP Affecting Non-Site-Admin Users
CVE-2026-10854

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-10854?

A visibility control issue in the event template creation workflow of MISP allowed non-site-admin users to access private galaxies owned by other organizations. This flaw occurred when the event template builder loaded all enabled galaxies without applying proper organization or distribution-based access restrictions, resulting in unauthorized exposure of sensitive galaxy metadata, including type and description. The vulnerability has been addressed by ensuring that non-site-admin users can only query galaxies owned by their organization or those with a non-private distribution setting, maintaining overall security for site administrators who still have visibility over all enabled galaxies.

Affected Version(s)

misp 0 <= 2.5.38

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
.