Junglewise Threat Intelligence

CVE-2026-10854: MISP Information Disclosure in Event Template Creation

CVE-2026-10854 · Severity: info · CVSS 5.3 · Published 2026-06-04

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP, an open-source threat intelligence platform, contained a flaw that allowed users to see private data belonging to other organizations. Specifically, when creating event templates, users could view metadata for 'galaxies' (clusters of related threat information) that should have been restricted to specific groups. While this does not allow for the modification of data, it could lead to the unauthorized disclosure of sensitive organizational descriptions and threat classifications.

Technical details

An information disclosure vulnerability (CWE-200) exists in the MISP EventTemplatesController. The event template builder workflow failed to apply organization-based or distribution-based access restrictions when loading enabled galaxies. As a result, an authenticated non-site-admin user could view private galaxy metadata, such as galaxy types and descriptions, that belonged to other organizations. The vulnerability was addressed by implementing a query filter that restricts galaxy visibility for non-admins to only those owned by the user's organization or those with a non-private distribution setting.

Affected products

  • MISP Project MISP Prior to commit d3adfe1a097dd4b403364e9af34e208660eeec1a

Timeline

  • 2026-06-04: advisory: CVE-2026-10854 published by CIRCL
  • 2026-06-04: patched: Fix committed to MISP repository (d3adfe1)

References