Incomplete Authorization Check in MISP cti-transmute Vulnerability
CVE-2026-72759

6.9MEDIUM

Key Information:

Vendor

Misp

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72759?

In certain versions of MISP cti-transmute, an authorization check within the conversion-history details endpoint was improperly implemented. This flaw allowed users to access the retained history of deleted conversions due to the software only enforcing access restrictions when the conversion object existed and had a visibility requirement. Consequently, users could potentially view sensitive historical data relating to deleted conversions, leading to unauthorized information disclosure. The vulnerability was addressed in a commit made on July 22, 2026, which corrected the logic to deny access if the conversion is missing or if the requester lacks sufficient permissions.

Affected Version(s)

cti-transmute 0 <= 1.4.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Christian Studer
.