🔐 CVE Alert

CVE-2026-94393

UNKNOWN 0.0

MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report’s UUID. Once moved, they could view and change information that they were not originally allowed to access. The vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID. The main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISP’s normal access restrictions. Version affected: <2.5.47

CWE CWE-639 CWE-284
Vendor misp
Product misp
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

MISP / MISP
0 < 2.5.47

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/MISP/MISP/commit/43665b9bb

Credits

iglocska Claude Opus 4.8 🔍 David André 🔍 Jeroen Pinoy