Impact
The vulnerability arises when the MISP Command Line Interface does not preserve the impersonated user ID in audit logs. The legacy SysLogLogable behaviour stores the identity in instance state, which can be overwritten when another model lazily attaches the shared behaviour. Consequently, actions performed via the CLI can be logged under the wrong user or as SYSTEM, and the logs lack the ‘via CLI’ marker that distinguishes command‑line operations from web‑based ones. The weakness is classified as CWE‑223 (Incorrect Authorization) and CWE‑778 (Unvalidated Input to File System Operation). The flaw does not provide a mechanism for arbitrary code execution or privilege escalation; rather, it undermines accountability and could hide malicious activity performed through the CLI.
Affected Systems
Affected environments are installations of the MISP application (vendor MISP) running version 2.5.45 or earlier. The issue is limited to setups that use the legacy interactive CLI for user impersonation.
Risk and Exploitability
CVSS 4.6 places the flaw in the low‑to‑medium severity range. EPSS is not available, and the vulnerability is not listed in CISA KEV, indicating no publicly known exploits. The most likely attack vector is a user or attacker with CLI access, which may already require privileged or administrative rights. Once that access is in place, the attacker can compromise the integrity of audit trails rather than directly attacking the system.
OpenCVE Enrichment