Executive brief
A vulnerability in the MISP threat intelligence platform allows authorized users to bypass security restrictions when editing events. By manipulating web form data, a user could assign an event to a restricted sharing group they are not supposed to access. This could lead to the unauthorized disclosure of private group names and the unintended modification of how sensitive threat data is distributed.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the MISP EventsController.php within the non-REST event editing path. While the REST API path correctly enforces sharing group authorization via Event::_edit(), the standard web form save path failed to validate the 'sharing_group_id' against the user's permissions when the distribution level was set to 'sharing group'. An authenticated attacker with event editing privileges can tamper with the HTTP request to assign events to unauthorized or undisclosed sharing groups. This results in the leakage of restricted sharing group names in event listings and unauthorized modification of distribution metadata. The issue has been addressed by implementing validation checks in the edit method to ensure the current user is authorized to use the selected sharing group.
Affected products
- MISP Project MISP Prior to commit 609ff6c785d7dae41d22ef43dda9347d34cd2a58
Timeline
- 2026-06-12: advisory: NVD publication date
- 2026-06-12: disclosed
- 2026-06-12: patched: Fix committed to MISP repository