Description
Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path.


The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different sharing_group_id, that authorization branch was skipped. Later, MISP’s field-recovery logic restored the existing event distribution from storage. For events already configured with sharing-group distribution, the unauthorized sharing-group ID could therefore be saved.


The fix adds authorization checks in both the controller and Event::_edit() whenever a non-empty sharing_group_id is supplied without distribution. The model now calls SharingGroup::checkIfAuthorised() before persisting the change.



Version affected: ≤2.5.45
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability arises when a MISP user edits an event without supplying a distribution value but includes a different sharing_group_id, causing the authorization check that verifies the user’s access to that sharing group to be bypassed. Because the system’s field‑recovery logic later restores the original distribution, the edited event can persist the unauthorized sharing_group_id, effectively allowing a user to add themselves to an event group they would normally be denied from accessing. This represents an authorization bypass (CWE‑862) that can lead to privilege escalation and exposure of sensitive threat‑intelligence data.

Affected Systems

Any MISP instance running version 2.5.45 or earlier is affected, including standard installations of the MISP MISP product. The vulnerability was closed in commit cf3ee4026, which introduced explicit checks for the sharing_group_id when the distribution field is omitted, and the fix is distributed in release 2.5.46 and later.

Risk and Exploitability

The CVSS score of 7.1 denotes high severity, while the EPSS score of less than 1 % indicates a low current likelihood of exploitation; the vulnerability is not listed in CISA’s KEV catalog. The attack is likely to occur through the authenticated event‑edit endpoint exposed by the web UI or REST API, requiring an authorized user to submit a request that omits the distribution field and supplies a new sharing_group_id. Even at low exploitation probability, the potential for privilege escalation makes remediation a priority.

Generated by OpenCVE AI on September 17, 2026 at 18:46 UTC.

Remediation

Vendor Solution

The fix adds an explicit authorization check for the sharing_group_id in the code path where the distribution field is omitted from the edit request. In the controller, if no distribution is submitted but a sharing_group_id is present and differs from the stored value, the user's access to that sharing group is verified via checkIfCanBeUsed before the edit proceeds. In the model's _edit method, a parallel check via checkIfAuthorised is added for the same condition, returning an error if the user is not authorized for the submitted sharing group. This closes the gap where omitting the distribution field bypassed the existing authorization gate.


OpenCVE Recommended Actions

  • Apply the official MISP patch that adds explicit authorization checks for sharing_group_id when distribution is omitted.
  • Upgrade to MISP 2.5.46 or newer to include the fix.
  • Restrict write access to the event‑edit API endpoint or web form to users who legitimately require it, reducing the opportunity for privilege escalation.
  • Enable logging of sharing_group_id modifications and review logs regularly to detect anomalous changes.

Generated by OpenCVE AI on September 17, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different sharing_group_id, that authorization branch was skipped. Later, MISP’s field-recovery logic restored the existing event distribution from storage. For events already configured with sharing-group distribution, the unauthorized sharing-group ID could therefore be saved. The fix adds authorization checks in both the controller and Event::_edit() whenever a non-empty sharing_group_id is supplied without distribution. The model now calls SharingGroup::checkIfAuthorised() before persisting the change. Version affected: ≤2.5.45
Title MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitted During Edit
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T14:19:38.987Z

Reserved: 2026-09-15T08:06:29.530Z

Link: CVE-2026-91825

cve-icon Vulnrichment

Updated: 2026-09-15T14:17:09.139Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T09:16:45.540

Modified: 2026-09-16T13:42:48.460

Link: CVE-2026-91825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses