Authorization Flaw in MISP Allows Unpermitted Deletion of Event Attributes
CVE-2026-85538

8.3HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85538?

An authorization flaw in MISP permits users with insufficient permissions to delete attributes from events. This vulnerability arises from inconsistencies in how permissions are checked during deletion compared to attribute editing. Users belonging to an organization associated with an event could exploit this flaw to delete attributes, potentially compromising the integrity of threat intelligence data. The recent patch addresses this issue by enforcing a consistent authorization check across all deletion processes, ensuring that only authorized users can modify event attributes.

Affected Version(s)

misp 0 <= 2.5.45

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
elhoim (David André)
Claude Opus 5 (1M context)
.