Junglewise Threat Intelligence

CVE-2026-10860: MISP CRUD component authorization bypass via HTTP DELETE

CVE-2026-10860 · Severity: info · CVSS 7.9 · Published 2026-06-04

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP, an open-source threat intelligence platform, contains a logic error in its data management component. This flaw allows users to bypass security checks and delete records they should not have permission to remove. This could lead to the unauthorized destruction of critical threat data and disrupt security operations.

Technical details

A logic error exists in the `CRUDComponent::delete` function of MISP due to improper operator precedence (missing parentheses). The vulnerable expression `($validationError === null && POST) || DELETE` evaluates to true whenever an HTTP DELETE request is used, regardless of whether `$validationError` contains a failure from the validation callback. An attacker can exploit this by sending a crafted HTTP DELETE request to an affected endpoint to bypass application-level authorization or validation checks. This allows for the unauthorized deletion of records. The issue has been addressed in the MISP codebase by correctly grouping the request method conditions within parentheses.

Affected products

  • MISP Project MISP Prior to commit a587755

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: patched: Fix committed in a5877559dc88ad7a0c935910a652c130489ae2bd

References