Authorization Flaw in MISP by MISP Project
CVE-2026-91825
7.1HIGH
What is CVE-2026-91825?
An authorization flaw exists in MISP that affects its handling of sharing group IDs under specific conditions. When a user attempts to edit an event and submits a sharing group ID without specifying its distribution, the system bypasses critical authorization checks. This oversight allows unauthorized users to save changes involving sensitive sharing group IDs, potentially exposing confidential information. The solution involves enhancing the authorization checks in the relevant controller to ensure that any non-empty sharing group ID is properly authorized before changes are stored. This ensures a more secure management of event sharing within MISP.
Affected Version(s)
MISP 0 < 2.5.46
