Impact
The vulnerability arises when a MISP user edits an event without supplying a distribution value but includes a different sharing_group_id, causing the authorization check that verifies the user’s access to that sharing group to be bypassed. Because the system’s field‑recovery logic later restores the original distribution, the edited event can persist the unauthorized sharing_group_id, effectively allowing a user to add themselves to an event group they would normally be denied from accessing. This represents an authorization bypass (CWE‑862) that can lead to privilege escalation and exposure of sensitive threat‑intelligence data.
Affected Systems
Any MISP instance running version 2.5.45 or earlier is affected, including standard installations of the MISP MISP product. The vulnerability was closed in commit cf3ee4026, which introduced explicit checks for the sharing_group_id when the distribution field is omitted, and the fix is distributed in release 2.5.46 and later.
Risk and Exploitability
The CVSS score of 7.1 denotes high severity, while the EPSS score of less than 1 % indicates a low current likelihood of exploitation; the vulnerability is not listed in CISA’s KEV catalog. The attack is likely to occur through the authenticated event‑edit endpoint exposed by the web UI or REST API, requiring an authorized user to submit a request that omits the distribution field and supplies a new sharing_group_id. Even at low exploitation probability, the potential for privilege escalation makes remediation a priority.
OpenCVE Enrichment