PT-2026-48998 · Misp · Misp

·

CVE-2026-54396

·

Published

2026-06-12

·

Updated

2026-06-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description An information disclosure issue exists in the AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown is populated using the AuthKey.user id value provided in the request data. An authenticated user with permissions to edit an AuthKey can submit arbitrary user IDs to observe the returned dropdown data, which enables the enumeration of user email addresses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54396

Affected Products

Misp