Insecure Direct Object Reference in MISP Event Model
CVE-2026-94374

8.3HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94374?

An insecure direct object reference vulnerability exists in the processModuleResultsData method of the MISP Event model. This flaw allows an authenticated user with the appropriate permissions to manipulate EventReport entries by submitting module results with a client-supplied 'id'. The MISP EventReport model's create() method does not properly remove the 'id' field, which can result in unintended data modifications. An attacker could exploit this vulnerability to read reports from different events, overwrite key fields with malicious data, or change report ownership, leading to data disclosure and integrity issues across events.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 4.8
.