Description
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging.


The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user.



Version affected: ≤2.5.45
Published: 2026-09-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Audit Log Impersonation
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises when the MISP Command Line Interface does not preserve the impersonated user ID in audit logs. The legacy SysLogLogable behaviour stores the identity in instance state, which can be overwritten when another model lazily attaches the shared behaviour. Consequently, actions performed via the CLI can be logged under the wrong user or as SYSTEM, and the logs lack the ‘via CLI’ marker that distinguishes command‑line operations from web‑based ones. The weakness is classified as CWE‑223 (Incorrect Authorization) and CWE‑778 (Unvalidated Input to File System Operation). The flaw does not provide a mechanism for arbitrary code execution or privilege escalation; rather, it undermines accountability and could hide malicious activity performed through the CLI.

Affected Systems

Affected environments are installations of the MISP application (vendor MISP) running version 2.5.45 or earlier. The issue is limited to setups that use the legacy interactive CLI for user impersonation.

Risk and Exploitability

CVSS 4.6 places the flaw in the low‑to‑medium severity range. EPSS is not available, and the vulnerability is not listed in CISA KEV, indicating no publicly known exploits. The most likely attack vector is a user or attacker with CLI access, which may already require privileged or administrative rights. Once that access is in place, the attacker can compromise the integrity of audit trails rather than directly attacking the system.

Generated by OpenCVE AI on September 15, 2026 at 14:16 UTC.

Remediation

Vendor Solution

The fix introduces a process-wide static identity (setShellUser) on SysLogLogableBehavior that is resolved at write time rather than at setup time, so it survives lazy model loads that re-run setup() on the singleton. The behavior appends 'via CLI' to the log description for shell-originated rows, mirroring the request_type = CLI marker in the new audit engine. The CLI shell now publishes the impersonated user through both Configure::write('CurrentUserId') and SysLogLogableBehavior::setShellUser() before any write. Explicit extralog calls were added for CLI user edit, disable, and delete operations so the default audit engine records them the same way the web path does. Background jobs that publish no user continue to log as SYSTEM without a CLI marker.


OpenCVE Recommended Actions

  • Update MISP to a version newer than 2.5.45, which includes the fix that sets a process‑wide static identity and adds the ‘via CLI’ marker to audit entries.
  • After the update, confirm that CLI‑originated actions appear with the correct user ID and the CLI marker in system logs.
  • If upgrading is not immediately feasible, restrict direct access to the MISP CLI to trusted administrators and consider removing or disabling the SysLogLogable behaviour from CLI‑only scripts to prevent identity loss.

Generated by OpenCVE AI on September 15, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user. Version affected: ≤2.5.45
Title MISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model Load
Weaknesses CWE-223
CWE-778
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-14T13:00:29.069Z

Reserved: 2026-09-14T12:37:52.348Z

Link: CVE-2026-90955

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:04.186Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:19:32.583

Modified: 2026-09-16T13:42:47.777

Link: CVE-2026-90955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-223

    Omission of Security-relevant Information

  • CWE-778

    Insufficient Logging