User Authorization Bypass in MISP Event Template Instantiation
CVE-2026-88915
What is CVE-2026-88915?
Certain versions of MISP exhibit a vulnerability where the system fails to adequately enforce user authorization during the instantiation of event templates. Specifically, templates with a distribution setting of 4 can define a sharing_group_id, but the process allows this identifier to be utilized without checking whether the user has the right to do so. Additionally, tags specified within the template can be added without validating the user's tagging permissions, which may lead to local-only tags being applied globally, thus violating their intended access restrictions. To rectify this, the latest updates have introduced checks for user permissions to utilize sharing groups and have ensured that tag modifications adhere to normal tagging criteria, thereby securing the integrity of sensitive tagging processes.
Affected Version(s)
MISP 0 <= 2.5.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
