PT-2026-96104 · Misp · Misp
CVSS v4.0
6.4
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.47
Description
An issue exists where the software identifies existing reports using a UUID without verifying if the report belongs to the same event. An attacker with editor access to at least one event who knows or can guess a valid report UUID can move a report from another event into their own. This allows the unauthorized viewing and modification of private event reports, bypassing standard access restrictions.
Recommendations
Update MISP to version 2.5.47 or later.
Fix
IDOR
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp