CVEFinder.io

CVE-2026-94393

๐Ÿ”ถ medium
๐Ÿ” Scan for this CVE
Summary

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the reportโ€™s UUID. Once moved, they could view and change information that they were not originally allowed to access. The vulnerability requires

Description

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event.

As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the reportโ€™s UUID. Once moved, they could view and change information that they were not originally allowed to access.

The vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID.

The main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISPโ€™s normal access restrictions.

Version affected: <2.5.47

CVSS Score
-
EPSS Score
0.4
Exploit Probability
Published Date
2026-09-21
First Seen: 2026-09-24
๐ŸŽฏ CISA SSVC Assessment Updated: Sep 21, 2026
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Partial
Limited system impact
๐Ÿ† Discovered By
iglocska (remediation developer) Claude Opus 4.8 (remediation developer) David Andrรฉ (reporter) Jeroen Pinoy (reporter)
SSVC data provided by CISA
Last Modified 2026-09-21
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 0

No affected products information available

๐Ÿ”— References 1