User Authorization Bypass in MISP Event Template Instantiation
CVE-2026-88915

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88915?

Certain versions of MISP exhibit a vulnerability where the system fails to adequately enforce user authorization during the instantiation of event templates. Specifically, templates with a distribution setting of 4 can define a sharing_group_id, but the process allows this identifier to be utilized without checking whether the user has the right to do so. Additionally, tags specified within the template can be added without validating the user's tagging permissions, which may lead to local-only tags being applied globally, thus violating their intended access restrictions. To rectify this, the latest updates have introduced checks for user permissions to utilize sharing groups and have ensured that tag modifications adhere to normal tagging criteria, thereby securing the integrity of sensitive tagging processes.

Affected Version(s)

MISP 0 <= 2.5.45

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scottish Government - National Cyber Team
iglocska
Claude Opus 5 (1M context)
.