Access Control Flaw in MISP EventReports Affects Users
CVE-2026-95685

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95685?

The MISP platform has revealed a significant access control flaw within its EventReports functionality. Specifically, the 'replaceSuggestionInReport' action has been erroneously linked to a wildcard permission ('*'), allowing any authenticated user to alter content in event reports without proper authorization. Unlike other report-modification actions that require specific permissions, this flaw permits unauthorized users to manipulate suggestion data. Consequently, this weakness poses a serious risk of corrupting threat intelligence data and possibly injecting deceptive information into reports used by analysts and automated systems alike.

Affected Version(s)

MISP 0 < 2.5.47

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
.