Executive brief
MISP is an open-source intelligence sharing platform used by organizations to collaborate on threat information. A flaw in the UiBeta theme's collection view allowed authenticated users to retrieve restricted event details (including sensitive metadata, tags, and threat intelligence clusters) without proper access controls, potentially exposing information they should not be permitted to see across the platform.
Technical details
The vulnerability is an authorization bypass in MISP's presentation layer (app/View/Themed/UiBeta/Collections/view.ctp). The controller correctly filtered events using per-user ACL checks via Event::fetchSimpleEvents($user, ...), but the view template independently re-queried the same event UUIDs using only an Event.uuid IN (...) condition, bypassing the createEventConditions() authorization filter. Since collection element UUIDs are stored without server-side authorization validation against referenced events, an authenticated user viewing a collection could retrieve full event details (identifiers, info, dates, creator organization, tags, galaxy clusters) regardless of their event-level permissions. This constitutes horizontal privilege escalation across event boundaries. A patch was released that applies the caller's ACL to the beta collection view's event lookup.
Affected products
- MISP MISP
Timeline
- 2026-09-06: disclosed
- 2026-09-06: patched: Commit 44573e4 applied ACL enforcement to collection view event lookup