Impact
The vulnerability in MISP core allows a lower‑privileged authenticated user to modify or delete data that belongs to a different organization. The flaw stems from incorrect authorization checks, where ownership was verified against an unrelated entity or omitted entirely, enabling cross‑organization actions such as removing event report tags, bulk deleting collection elements, overwriting analyst data, editing other templates, and remapping decaying models. An attacker can therefore corrupt shared intelligence, compromise data integrity, and disrupt analyst workflows.
Affected Systems
The affected product is MISP core. No specific version information is listed in the CVE data; the impact applies to any version that has not incorporated the commits referenced in the CVE references. Administrators should verify that the deployed version is up to date or at least exclude the vulnerable code paths described.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability, but the EPSS score is not available so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires an authenticated user who possesses subsystem‑specific feature permissions; no elevated user level or remote code execution is necessary, but the user must be able to access the affected write paths.
OpenCVE Enrichment