Incomplete Authorization Check in MISP cti-transmute Vulnerability
CVE-2026-72759
6.9MEDIUM
What is CVE-2026-72759?
In certain versions of MISP cti-transmute, an authorization check within the conversion-history details endpoint was improperly implemented. This flaw allowed users to access the retained history of deleted conversions due to the software only enforcing access restrictions when the conversion object existed and had a visibility requirement. Consequently, users could potentially view sensitive historical data relating to deleted conversions, leading to unauthorized information disclosure. The vulnerability was addressed in a commit made on July 22, 2026, which corrected the logic to deny access if the conversion is missing or if the requester lacks sufficient permissions.
Affected Version(s)
cti-transmute 0 <= 1.4.0
