Junglewise Threat Intelligence

CVE-2026-56423: MISP broken access control in bulk deletion handlers

CVE-2026-56423 · Severity: info · CVSS 9.4 · Published 2026-06-22

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP, an open-source threat intelligence platform, contained a security flaw in how it handled bulk deletions of event reports and sharing groups. An authenticated user with basic permissions could delete data belonging to other organizations across the entire system. This could lead to the permanent loss of critical threat intelligence data and sharing configurations, potentially disrupting collaborative security operations.

Technical details

A broken access control vulnerability (CWE-862) exists in MISP Core's bulk deletion handlers. The 'deleteSelection' methods in both EventReportsController and SharingGroupsController relied on global role-level permissions (perm_add and perm_sharing_group, respectively) rather than validating per-object ownership. An authenticated attacker can provide IDs or UUIDs of objects belonging to other organizations to the bulk deletion endpoints to perform unauthorized hard-deletes instance-wide. The vulnerability was addressed by implementing per-item authorization checks using 'fetchIfAuthorized' and 'checkIfOwner' within the deletion callbacks. Patches are available in the MISP GitHub repository.

Affected products

  • MISP Project MISP <= 2.5.41

Timeline

  • 2026-06-22: advisory: CVE-2026-56423 published by CIRCL
  • 2026-06-22: disclosed

References