Executive brief
MISP is an open-source threat intelligence platform used by organizations to share and collaborate on security incidents and malware analysis. A flaw in the attribute deletion feature allowed authenticated users to remove threat intelligence data from events even if their assigned role did not grant them permission to modify those events, potentially leading to unauthorized loss or tampering of critical security information.
Technical details
The vulnerability is an authorization bypass (privilege escalation) in MISP's attribute deletion logic. The affected paths in MispAttribute::deleteAttribute() relied solely on organization membership checks and failed to enforce the standard perm_modify and perm_modify_org permission requirements that are correctly applied to attribute editing operations. An authenticated attacker with membership in the organization owning an event could exploit this inconsistency to delete individual or bulk attributes from events they were not authorized to modify. The flaw was patched by introducing authorization checks that now validate users against the same ACL::canModifyEvent() logic used for normal event and attribute modification before allowing any deletion.
Affected products
- MISP MISP
Timeline
- 2026-09-04: disclosed