Junglewise Threat Intelligence

CVE-2026-10855: MISP authorization bypass in Event Template Importer

CVE-2026-10855 · Severity: info · CVSS 5.1 · Published 2026-06-04

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

An authorization flaw in the MISP threat intelligence platform allowed users to overwrite event templates belonging to other organizations. MISP is used by security teams to share and analyze cyber threat information; event templates define how this data is structured. An attacker could use this flaw to modify the structure or metadata of templates used by other groups, potentially disrupting data sharing workflows or corrupting threat intelligence records.

Technical details

A missing authorization check (CWE-862) existed in the MISP Event Template Importer's overwrite workflow. While the application verified if a matching template existed during an import, it failed to validate that the user performing the overwrite belonged to the organization that owned the existing template. An authenticated attacker with template import privileges could exploit this to modify the structure, attributes, or metadata of templates belonging to different organizations. Site administrators are unaffected as they have legitimate cross-organization permissions. The vulnerability was addressed in commit 7c2200d by enforcing an ownership check for non-admin users.

Affected products

  • MISP Project MISP Prior to commit 7c2200d

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory

References