Impact
A flaw in MISP event template instantiation allows a user to bind a created event to any sharing group ID and to attach arbitrary tags, including those marked local_only, without proper authorization checks. This bypasses the intended permission model and leads to misuse of sharing groups and propagation of tags across synchronized feeds. The vulnerability is a classic privilege escalation scenario driven by missing authorization (CWE-862).
Affected Systems
The vulnerability affects all versions of MISP up to and including 2.5.45; no other product versions are documented as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a normal user action within the MISP web interface, requiring an authenticated user to trigger template instantiation. Successful exploitation would permit the attacker to create events that belong to arbitrary sharing groups and carry tags they would normally be prohibited from attaching, potentially expanding their visibility and causing broader data leakage or unintended tag synchronization.
OpenCVE Enrichment