Impersonation Logging Issue in MISP CLI Shell by MISP
CVE-2026-90955

4.6MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90955?

The interactive command-line interface (CLI) shell of MISP has a vulnerability that affects how it logs user actions. Specifically, when a user impersonates another MISP user via the CLI, the identity of the impersonated user may not be correctly preserved in the audit logs. This occurs due to legacy behavior in the SysLogLogable component, which can be overwritten causing subsequent commands to lose their intended user attribution. Additionally, records generated from the CLI do not have a clear indication that they originated from the CLI, making them indistinguishable from standard web actions by the user, leading to potential security and accountability issues. The affected versions of this product are those prior to or equal to 2.5.45. For more information, refer to the security patch.

Affected Version(s)

MISP 0 < 2.5.46

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scottish Government - National Cyber Team
iglocska
Claude Fable 5.1
.