Executive brief
MISP, an open-source threat intelligence platform, contains a security flaw where organization-based access restrictions for certain data import modules are not properly enforced. An authenticated user who knows the name of a restricted module can bypass these controls to use tools that their organization should not have access to. This could lead to unauthorized modification or import of threat intelligence data, potentially compromising the integrity of shared security information.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in MISP's `importModule()` function. The root cause is that `importModule()` utilizes `getEnabledModule()` to resolve modules by name, but this specific lookup path failed to implement the `canUse()` organization restriction check that is present in the broader `getEnabledModules()` function. An authenticated attacker with knowledge of a restricted module's name can bypass `Plugin.Import_<module>_restrict` settings. This allows the attacker to execute restricted import functionality, potentially leading to unauthorized modification of event data. A fix has been committed to the MISP repository to enforce organization checks when a user context is provided to the module loader.
Affected products
- MISP MISP <= 2.5.42
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched: Fix committed to GitHub repository