CVEFinder.io

CVE-2026-56424

⚠️ high
🔍 Scan for this CVE
Summary

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cause the application to authorize one object but mutate another, or could modify objects that were merely visible rather than editable by the user’s organization. The affected paths included: * Ev

Description

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cause the application to authorize one object but mutate another, or could modify objects that were merely visible rather than editable by the user’s organization.


The affected paths included:

* Event Reports tag removal: the route-authorized report could differ from the report ID used for tag detachment, enabling cross-organization tag removal from another event report




* Collection Elements bulk deletion: bulk deletion authorized against a collection whose ID matched the collection-element row ID, rather than the element’s actual parent collection, enabling deletion of elements from collections the user did not own.
* Analyst Data capture/update: nested analyst data updates could overwrite an existing record without applying the normal canEditAnalystData ownership check, enabling cross-organization overwrite of analyst data records.
* Template Elements editing: editing authorized against a template whose ID matched the template-element ID, rather than the element’s actual parent template, enabling unauthorized edits to another organization’s template elements.
* Decaying Model editing and mappings: write paths loaded models using view-scope access but did not verify edit ownership, enabling users to edit or remap visible models owned by another organization. 








Successful exploitation could allow an authenticated user with subsystem-specific permissions to perform unauthorized cross-organization modifications or deletions of MISP data, resulting in integrity loss, unauthorized tampering with shared intelligence, and disruption of analyst workflows.

CVSS Score
8.8
High
EPSS Score
0.4
Exploit Probability
Published Date
2026-06-22
First Seen: 2026-06-25
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 80.8% of all 360,673 vulnerabilities in our database.

#69,256
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jun 23, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Andras Iklody (remediation developer) Jeroen Pinoy (analyst) Claude (the international export version) (tool)
SSVC data provided by CISA
Last Modified 2026-06-23
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-86342 🔶 medium 4.3 0.2 Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview ... 2026-09-07
CVE-2026-86347 🔶 medium 6.5 0.3 Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry... 2026-09-07
CVE-2026-86351 🔶 medium 6.1 0.2 Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with... 2026-09-07
CVE-2026-86408 🔶 medium 6.5 0.2 Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKe... 2026-09-07
CVE-2026-86417 🔶 medium 4.3 0.2 Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). T... 2026-09-07
CVE-2026-86418 🔶 medium 4.3 0.2 Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the sa... 2026-09-07
These CVEs affect the same products