Authorization Flaw in MISP Event Template Importer by MISP
CVE-2026-10855

5.1MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-10855?

An authorization flaw in the MISP Event Template Importer enables authenticated users to overwrite event templates owned by other organizations without proper ownership verification. This vulnerability arises during the overwrite process when importing event templates, as the application fails to confirm that the user importing the template belongs to the same organization as the existing template. This could result in unauthorized modifications of crucial event data, including structure and metadata, potentially impacting workflows for other organizations. Affected users who do not possess site administrator privileges can only overwrite templates from their own organization, a restriction which is not applicable to site administrators.

Affected Version(s)

misp 0 <= 2.5.38

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
Jeroen Pinoy
.