Impact
The vulnerability arises from a type mismatch in a database VARCHAR field as an integer during permission checks, letting non‑privileged users bypass ACL constraints and view dashboard templates that should be restricted. The result is a privilege escalation where an attacker can see and use content they are not authorized to access, compromising confidentiality of restricted dashboards.
Affected Systems
MISP system versions up to and including 2.5.45 are affected. The issue occurs in the MISP::MISP product when the restrict_to_permission_flag column, storing strings like perm_site_admin, is compared to the integer zero during template listing.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need web access to the MISP instance and the ability to trigger the template listing function, typically available to all authenticated users, making the attack vector likely via the web interface.
OpenCVE Enrichment