Junglewise Threat Intelligence

CVE-2026-61474: MISP improper authorization in attribute creation endpoint

CVE-2026-61474 · Severity: info · CVSS 5.3 · Published 2026-07-09

Technologies: Misp. Vendors: Misp.

Executive brief

MISP, an open-source threat intelligence platform, contains a security flaw in how it handles data sharing permissions. An authorized user could bypass intended restrictions to link information to private sharing groups they are not supposed to access. This could lead to unauthorized data associations and compromise the integrity of sensitive sharing relationships within the platform.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the AttributesController.php of MISP. The application previously only performed a sharing group permission check if the 'distribution' value was explicitly set to 4 ("sharing group"). An authenticated attacker with attribute creation permissions could bypass this by submitting a 'sharing_group_id' while using a different distribution value, allowing them to reference restricted sharing groups. The fix modifies the logic to enforce the `__canUseSharingGroup` check whenever a 'sharing_group_id' is provided, regardless of the distribution setting.

Affected products

  • MISP MISP <= 2.5.42

Timeline

  • 2026-07-09: advisory
  • 2026-07-09: disclosed

References