Access Control Flaw in MISP EventReports Affects Users
CVE-2026-95685
5.3MEDIUM
What is CVE-2026-95685?
The MISP platform has revealed a significant access control flaw within its EventReports functionality. Specifically, the 'replaceSuggestionInReport' action has been erroneously linked to a wildcard permission ('*'), allowing any authenticated user to alter content in event reports without proper authorization. Unlike other report-modification actions that require specific permissions, this flaw permits unauthorized users to manipulate suggestion data. Consequently, this weakness poses a serious risk of corrupting threat intelligence data and possibly injecting deceptive information into reports used by analysts and automated systems alike.
Affected Version(s)
MISP 0 < 2.5.47
