Organisation Metadata Exposure in MISP by the Vendor
CVE-2026-86418

2.3LOW

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86418?

A vulnerability in MISP versions up to and including 2.5.45 allows authenticated users to access organisation metadata through the dashboard organisation picker without appropriate visibility restrictions. When the Security.hide_organisation_index_from_users setting is enabled, normal organisation enumeration is limited; however, the dashboard picker continues to query all organisations, revealing sensitive information about organisations that should remain concealed. The issue arises because the picker does not adhere to the same restrictions enforced in other views. This flaw may lead to the unintended exposure of sensitive organisations to users who should not have access to that information.

Affected Version(s)

MISP 0 <= 2.5.45

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scottish Government - National Cyber Team
iglocska
Claude Opus 5 (1M context)
.