Insecure Direct Object Reference in MISP Event Model
CVE-2026-94374
8.3HIGH
What is CVE-2026-94374?
An insecure direct object reference vulnerability exists in the processModuleResultsData method of the MISP Event model. This flaw allows an authenticated user with the appropriate permissions to manipulate EventReport entries by submitting module results with a client-supplied 'id'. The MISP EventReport model's create() method does not properly remove the 'id' field, which can result in unintended data modifications. An attacker could exploit this vulnerability to read reports from different events, overwrite key fields with malicious data, or change report ownership, leading to data disclosure and integrity issues across events.
Affected Version(s)
MISP 0 < 2.5.47
