πŸ” CVE Alert

CVE-2026-103858

UNKNOWN 0.0

MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48

CWE CWE-285
Vendor misp
Product misp
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

MISP / MISP
unspecified < 2.5.48

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/MISP/MISP/commit/79fbd4c75

Credits

πŸ” Bastien Bossiroy and CΓ©lien Desteucq of NCIA iglocska Claude Opus 5.5 (1M context)