Impact
An authorization bypass in MISP's‑only users modify. When an import module returns data in the misp_standard format, the write path does not verify event modification rights before saving, enabling a user with read‑only event view access to inject or alter event content, thus compromising the integrity of MISP event data. This flaw represents a Missing Authorization issue (CWE‑862).
Affected Systems
The vulnerability affects the MISP platform (misp:misp). Specific affected versions are not enumerated in the CVE record, so any deployed release prior to the containment commit may be vulnerable. Users of MISP should check view permissions to persist data to events they should not modify. When an import module returns results in misp_standard format, the write path skips the modification‑rights check, allowing a read‑only user to inject or alter event data, thereby compromising the integrity of MISP event content.
Risk and Exploitability
The CVSS score of a moderate level of risk. The EPSS score of < 1% indicates a very low likelihood of exploitation in the wild, and the issue is not listed in the CISA KEV catalog, suggesting no publicly documented exploitation yet. The likely attack vector is through authenticated access—any actor with view‑only rights to an event importModule call can exploit the flaw, allowing unauthorized alteration of event data, undermining data integrity and potentially spreading misinformation within MISP. However, no exploits have been reported at the time of this analysis.
OpenCVE Enrichment