Description
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception.


Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls AccessLog::logRequest() twice for one HTTP request. The second deferred writer measures the error-controller execution instead of the original request and can overwrite the row created by the first pass. The corrupted fields include request duration, SQL query count, memory usage, and potentially the recorded query log.


The bug was masked because the same model instance retained the ID of the first saved row, causing the later save to issue an UPDATE rather than insert an obvious duplicate row.

Version affected: ≤2.5.45
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability causes the AccessLog model to record duplicate log entries for the same HTTP request. When an exception occurs, CakePHP runs the application startup path a second time, leading to a second call to AccessLog::logRequest() during the same request. The second call overwrites the original log row, corrupting fields such as request duration, SQL query count, memory usage, and potentially the query log, thereby destroying forensic data and compromising audit integrity. The flaw is a result of improper response handling (CWE‑223) and unsafe shared resource usage (CWE‑778).

Affected Systems

MISP instances running version 2.5.45 or earlier are affected. The issue applies to any M, because the AccessLog model reuses a single instance and retains the row ID.

Risk and Exploitability

Based on the description, it is inferred that an attacker could trigger the double‑write by causing an exception – for example, by sending malformed data that leads to a fatal error a CVSS v3.1 score of 5.3, the vulnerability is classified as moderate severity. The EPSS score is less than 1 %, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The impact is limited to the integrity of audit logs; no elevation of privilege or direct data theft occurs.

Generated by OpenCVE AI on September 17, 2026 at 17:56 UTC.

Remediation

Vendor Solution

The fix introduces a per-instance boolean guard ($deferredWriterRegistered) in the AccessLog model so that logRequest() returns early on the second beforeFilter pass, preventing the error controller from overwriting the original request's log entry. Additionally, a $this->create() call is added before $this->save() in saveOnShutdown() to ensure each save issues an INSERT rather than an UPDATE, providing defense-in-depth against accidental row mutation.


OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.46 or later, which introduces a per‑instance guard to prevent the second beforeFilter write and ensures each log entry is inserted as a new record.
  • If an upgrade is not immediately possible, apply the official patch commit 0dae5c072 or a compatible change that adds the $deferredWriterRegistered guard and forces an INSERT in saveOnShutdown(), preventing accidental row mutation.
  • As a temporary mitigation, disable logging for requests that trigger the error controller or configure the application to skip the second startup path, and review existing logs for any overwritten entries to assess the extent of corruption.

Generated by OpenCVE AI on September 17, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls AccessLog::logRequest() twice for one HTTP request. The second deferred writer measures the error-controller execution instead of the original request and can overwrite the row created by the first pass. The corrupted fields include request duration, SQL query count, memory usage, and potentially the recorded query log. The bug was masked because the same model instance retained the ID of the first saved row, causing the later save to issue an UPDATE rather than insert an obvious duplicate row. Version affected: ≤2.5.45
Title MISP Access Log Entry Overwritten by Error Controller's Second beforeFilter Pass
Weaknesses CWE-223
CWE-778
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T13:05:17.132Z

Reserved: 2026-09-15T09:26:32.260Z

Link: CVE-2026-91859

cve-icon Vulnrichment

Updated: 2026-09-15T13:05:10.795Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T10:17:06.470

Modified: 2026-09-16T13:42:48.993

Link: CVE-2026-91859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-223

    Omission of Security-relevant Information

  • CWE-778

    Insufficient Logging