PT-2026-96093 · Misp · Misp

·

CVE-2026-94374

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.47
Description An insecure direct object reference exists in the processModuleResultsData() function of the Event model. When processing module results, the system fails to unset the client-supplied id field for EventReport entries before saving. Since the create() method of the EventReport model does not strip this field, an authenticated user with permissions to submit module results can provide an id referencing a report from a different event. This allows the user to bypass authorization to read the content of another event's report by reparenting it, overwrite report fields with controlled data, or change the event id to redirect ownership, leading to cross-event data disclosure and integrity compromise.
Recommendations Update to version 2.5.47 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94374

Affected Products

Misp