Access Control Flaws in MISP's Interactive CLI Shell from MISP
CVE-2026-90895
What is CVE-2026-90895?
MISP’s interactive CLI shell contains vulnerabilities due to inadequate access control mechanisms that diverge from its web application. These inconsistencies can lead to unauthorized data access, exposing sensitive information for users without proper permissions. For instance, feed listings fail to apply lookup restrictions, allowing non-host organization users to access restricted data. Additionally, unauthorized users might gain visibility into feed details and potentially sensitive HTTP authorization credentials. Notably, CLI outputs are not properly sanitized, which can result in exposing authentication keys and group sharing details. Furthermore, pagination and terminal rendering have been enhanced in this patch to mitigate risks, but the core issue remains the lack of synchronization in authorization checks between CLI and web interface, significantly jeopardizing user data security.
Affected Version(s)
MISP 0 < 2.5.46
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
