Description
Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag.


DashboardsController::listTemplates() allowed a template when either:



 - its restrict_to_permission_flag matched one of the current user’s permission flags, or

 - restrict_to_permission_flag equaled integer 0






However, restrict_to_permission_flag is a varchar. MySQL therefore performed numeric coercion when comparing the column against integer 0. Strings such as perm_site_admin convert numerically to zero, making expressions such as perm_site_admin = 0 evaluate true and causing the “unrestricted” branch to match permission-restricted templates as well.



Version affected: ≤2.5.45
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Dashboard Templates
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from a type mismatch in a database VARCHAR field as an integer during permission checks, letting non‑privileged users bypass ACL constraints and view dashboard templates that should be restricted. The result is a privilege escalation where an attacker can see and use content they are not authorized to access, compromising confidentiality of restricted dashboards.

Affected Systems

MISP system versions up to and including 2.5.45 are affected. The issue occurs in the MISP::MISP product when the restrict_to_permission_flag column, storing strings like perm_site_admin, is compared to the integer zero during template listing.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need web access to the MISP instance and the ability to trigger the template listing function, typically available to all authenticated users, making the attack vector likely via the web interface.

Generated by OpenCVE AI on September 17, 2026 at 18:29 UTC.

Remediation

Vendor Solution

The fix corrects the type mismatch in the permission flag comparison by replacing the integer literal 0 with the explicit string values '' and '0', which are the actual database values representing an unrestricted dashboard template. This ensures MySQL performs a proper string-to-string comparison, so only rows genuinely marked as unrestricted are returned, restoring the intended per-permission-level access control on dashboard templates.


OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.46 or later, which applies the official fix that replaces the integer literal with the explicit string values '' and '0'.
  • Verify that the restriction logic for dashboard templates is functioning correctly by attempting to access templates with restricted permission flags.
  • Review and enforce least privilege on user roles to reduce exposure until the patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one of the current user’s permission flags, or  - restrict_to_permission_flag equaled integer 0 However, restrict_to_permission_flag is a varchar. MySQL therefore performed numeric coercion when comparing the column against integer 0. Strings such as perm_site_admin convert numerically to zero, making expressions such as perm_site_admin = 0 evaluate true and causing the “unrestricted” branch to match permission-restricted templates as well. Version affected: ≤2.5.45
Title MISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in Permission Flag Comparison
Weaknesses CWE-697
CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T13:29:55.108Z

Reserved: 2026-09-15T08:49:59.734Z

Link: CVE-2026-91851

cve-icon Vulnrichment

Updated: 2026-09-15T13:29:48.856Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T09:16:46.110

Modified: 2026-09-16T13:42:48.950

Link: CVE-2026-91851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses