Misp · Misp · CVE-2026-95805
**Name of the Vulnerable Software and Affected Versions**
MISP (affected versions not specified)
**Description**
A typo in the ACLComponent access control configuration causes the ACL rule for the `previewEventAttributes` action to reference the permission string `theming enabled*` instead of `theming enabled`. Because the malformed key does not match any valid permission identifier, the access control check for the `previewEventAttributes` endpoint malfunctions. This can lead to an authorization bypass, allowing unauthorized users to access sensitive indicator and attribute data, or cause an availability impact where legitimate users are denied access.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.