PT-2026-48994 · Misp · Misp
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
An incorrect visibility condition in the event template builder allows authenticated non-site-admin users to view galaxies that should not be visible to their organization. The issue stems from a custom access-control condition that uses a PHP comparison expression instead of a query condition to restrict galaxies to those owned by the user's organization or distributed beyond it. Consequently, enabled galaxies, including organization-only custom galaxies belonging to other organizations, may be exposed in the template builder galaxy list, potentially disclosing metadata about private galaxy definitions to unauthorized users.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp