CVE-2026-91825
MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitted During Edit
Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different sharing_group_id, that authorization branch was skipped. Later, MISPβs field-recovery logic restored the existing event distribution from storage. For events already configured with sharing-group distribution, the unauthorized sharing-group ID could therefore be saved. The fix adds authorization checks in both the controller and Event::_edit() whenever a non-empty sharing_group_id is supplied without distribution. The model now calls SharingGroup::checkIfAuthorised() before persisting the change. Version affected: β€2.5.45
| CWE | CWE-862 |
| Vendor | misp |
| Product | misp |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Get instant alerts for misp misp
Be the first to know when new unknown vulnerabilities affecting misp misp are published β delivered to Slack, Telegram or Discord.