Access Control Bypass in MISP Product by MISP Vendor
CVE-2026-86347
7.1HIGH
What is CVE-2026-86347?
An access control vulnerability in MISP allows authenticated users to exploit the uploadFile() function due to insufficient ACL restrictions. This flaw permits low-privileged users to upload files, consequently consuming server disk space without necessary permissions. Although the vulnerability does not enable arbitrary file overwrite or remote code execution, it poses risks associated with unchecked file uploads. Recent updates have patched the ACL requirement to prevent unauthorized access, ensuring greater security for overall template management operations.
Affected Version(s)
MISP 0 <= 2.5.45
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Scottish Government - National Cyber Team
iglocska
Claude Opus 5 (1M context)
