Authorization Flaw in MISP by MISP Project
CVE-2026-91825

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91825?

An authorization flaw exists in MISP that affects its handling of sharing group IDs under specific conditions. When a user attempts to edit an event and submits a sharing group ID without specifying its distribution, the system bypasses critical authorization checks. This oversight allows unauthorized users to save changes involving sensitive sharing group IDs, potentially exposing confidential information. The solution involves enhancing the authorization checks in the relevant controller to ensure that any non-empty sharing group ID is properly authorized before changes are stored. This ensures a more secure management of event sharing within MISP.

Affected Version(s)

MISP 0 < 2.5.46

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iglocska
Claude Opus 5 (1M context)
.