Authorization Flaws in MISP Core Affecting Multiple User Permissions
CVE-2026-56424
7.1HIGH
What is CVE-2026-56424?
The MISP Core contains multiple access control flaws that allow authenticated users with certain permissions to perform unauthorized actions. Specifically, users can alter or delete data across organizations, posing a significant risk to data integrity and security. The flaws arise due to improper authorization checks, enabling users to manipulate objects that should be restricted to their own organization. This includes unauthorized tag removal from event reports, bulk deletions of collection elements, and overwriting of analyst data records. Successful exploitation can disrupt workflows and compromise shared intelligence across collaborating environments.
Affected Version(s)
misp 0 <= 2.5.41
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andras Iklody
Jeroen Pinoy
Claude (the international export version)
