Authorization Flaws in MISP Core Affecting Multiple User Permissions
CVE-2026-56424

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-56424?

The MISP Core contains multiple access control flaws that allow authenticated users with certain permissions to perform unauthorized actions. Specifically, users can alter or delete data across organizations, posing a significant risk to data integrity and security. The flaws arise due to improper authorization checks, enabling users to manipulate objects that should be restricted to their own organization. This includes unauthorized tag removal from event reports, bulk deletions of collection elements, and overwriting of analyst data records. Successful exploitation can disrupt workflows and compromise shared intelligence across collaborating environments.

Affected Version(s)

misp 0 <= 2.5.41

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
Jeroen Pinoy
Claude (the international export version)
.