Impersonation Logging Issue in MISP CLI Shell by MISP
CVE-2026-90955
What is CVE-2026-90955?
The interactive command-line interface (CLI) shell of MISP has a vulnerability that affects how it logs user actions. Specifically, when a user impersonates another MISP user via the CLI, the identity of the impersonated user may not be correctly preserved in the audit logs. This occurs due to legacy behavior in the SysLogLogable component, which can be overwritten causing subsequent commands to lose their intended user attribution. Additionally, records generated from the CLI do not have a clear indication that they originated from the CLI, making them indistinguishable from standard web actions by the user, leading to potential security and accountability issues. The affected versions of this product are those prior to or equal to 2.5.45. For more information, refer to the security patch.
Affected Version(s)
MISP 0 < 2.5.46
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
