Description
MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.

As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:

- Read the thread title and the content of the quoted post

- Submit a new post into the discussion thread

This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).

Affected: <2.5.48
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Read and Post Access to Discussions
Action: Immediate Patch
AI Analysis

Impact

MISP implements a discussion posting feature that was designed to restrict access to threads based on organization membership. In this vulnerability, the application only verified whether a thread was flagged as restricted to a single organization. It failed to enforce the broader thread access control list that includes sharing-group membership and event-level visibility. As a result, an authenticated user who does not belong to the sharing group or lack visibility on the corresponding event can read the thread title, view the content of quoted posts, and append new messages to the discussion thread. The data disclosure extends to restricted thread metadata and post content, while the integrity impact allows injection of unauthorized messages.

Affected Systems

The vulnerability affects MISP deployments running versions earlier than 2.5.48.

Risk and Exploitability

The vulnerability scores a CVSS of 5.3, indicating moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. An attacker must be authenticated to a MISP instance and have access to the application’s posting interface. Because the flaw is limited to threads that are incorrectly checked for organization-only distribution, the most likely attack vector is an internal authenticated user exploiting the posting function. The exploitation requires no special configuration beyond normal user credentials, and the attacker can gain information disclosure and tamper with discussions within the organization.

Generated by OpenCVE AI on October 1, 2026 at 12:25 UTC.

Remediation

Vendor Solution

The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.


OpenCVE Recommended Actions

  • Upgrade to MISP 2.5.48 or later, which replaces the incomplete thread authorization check with a call to the full authorization method 'checkIfAuthorised' and adds a null check for posts without a valid thread association.
  • After upgrading, adjust user group permissions so that only members of the relevant sharing groups have posting rights on discussions to limit exposure.
  • Monitor activity logs for unexpected discussion posts and audit thread visibility settings to ensure that event-level visibility controls are properly enforced.

Generated by OpenCVE AI on October 1, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48
Title MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-01T11:31:32.840Z

Reserved: 2026-10-01T11:31:31.101Z

Link: CVE-2026-103858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T12:17:16.080

Modified: 2026-10-01T12:17:16.213

Link: CVE-2026-103858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:30:07Z

Weaknesses