Organisation Metadata Exposure in MISP by the Vendor
CVE-2026-86418
What is CVE-2026-86418?
A vulnerability in MISP versions up to and including 2.5.45 allows authenticated users to access organisation metadata through the dashboard organisation picker without appropriate visibility restrictions. When the Security.hide_organisation_index_from_users setting is enabled, normal organisation enumeration is limited; however, the dashboard picker continues to query all organisations, revealing sensitive information about organisations that should remain concealed. The issue arises because the picker does not adhere to the same restrictions enforced in other views. This flaw may lead to the unintended exposure of sensitive organisations to users who should not have access to that information.
Affected Version(s)
MISP 0 <= 2.5.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
