PT-2026-96785 · Misp · Misp

·

CVE-2026-95805

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A typo in the ACLComponent access control configuration causes the ACL rule for the previewEventAttributes action to reference the permission string theming enabled* instead of theming enabled. Because the malformed key does not match any valid permission identifier, the access control check for the previewEventAttributes endpoint malfunctions. This can lead to an authorization bypass, allowing unauthorized users to access sensitive indicator and attribute data, or cause an availability impact where legitimate users are denied access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95805

Affected Products

Misp