Misp · Misp · CVE-2026-94393
**Name of the Vulnerable Software and Affected Versions**
MISP versions prior to 2.5.47
**Description**
An issue exists where the software identifies existing reports using a UUID without verifying if the report belongs to the same event. An attacker with editor access to at least one event who knows or can guess a valid report UUID can move a report from another event into their own. This allows the unauthorized viewing and modification of private event reports, bypassing standard access restrictions.
**Recommendations**
Update MISP to version 2.5.47 or later.