Access Control Bypass in MISP Product by MISP Vendor
CVE-2026-86347

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86347?

An access control vulnerability in MISP allows authenticated users to exploit the uploadFile() function due to insufficient ACL restrictions. This flaw permits low-privileged users to upload files, consequently consuming server disk space without necessary permissions. Although the vulnerability does not enable arbitrary file overwrite or remote code execution, it poses risks associated with unchecked file uploads. Recent updates have patched the ACL requirement to prevent unauthorized access, ensuring greater security for overall template management operations.

Affected Version(s)

MISP 0 <= 2.5.45

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scottish Government - National Cyber Team
iglocska
Claude Opus 5 (1M context)
.