Authorization Flaw in MISP Allows Unpermitted Deletion of Event Attributes
CVE-2026-85538
8.3HIGH
What is CVE-2026-85538?
An authorization flaw in MISP permits users with insufficient permissions to delete attributes from events. This vulnerability arises from inconsistencies in how permissions are checked during deletion compared to attribute editing. Users belonging to an organization associated with an event could exploit this flaw to delete attributes, potentially compromising the integrity of threat intelligence data. The recent patch addresses this issue by enforcing a consistent authorization check across all deletion processes, ensuring that only authorized users can modify event attributes.
Affected Version(s)
misp 0 <= 2.5.45
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andras Iklody
elhoim (David André)
Claude Opus 5 (1M context)
