Authorization Flaw in MISP Event Template Importer by MISP
CVE-2026-10855
What is CVE-2026-10855?
An authorization flaw in the MISP Event Template Importer enables authenticated users to overwrite event templates owned by other organizations without proper ownership verification. This vulnerability arises during the overwrite process when importing event templates, as the application fails to confirm that the user importing the template belongs to the same organization as the existing template. This could result in unauthorized modifications of crucial event data, including structure and metadata, potentially impacting workflows for other organizations. Affected users who do not possess site administrator privileges can only overwrite templates from their own organization, a restriction which is not applicable to site administrators.
Affected Version(s)
misp 0 <= 2.5.38
