Junglewise Threat Intelligence

CVE-2026-86347: MISP ACL bypass in TemplatesController uploadFile

CVE-2026-86347 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: Misp. Vendors: Misp.

Executive brief

MISP is an open-source threat intelligence platform used by organizations to share and manage malware samples and security data. A flaw in its file-upload access controls allows any authenticated user—including those with read-only privileges—to repeatedly upload files to the server, consuming disk space without the required administrative permissions. While uploaded files cannot be directly executed or accessed via the web, this enables denial-of-service attacks that could degrade platform availability.

Technical details

A wildcard ACL entry ("*") in TemplatesController::uploadFile() incorrectly granted access to any authenticated user, bypassing intended role-based restrictions requiring perm_add or perm_template permissions. The upload handler accepts arbitrary file content with minimal validation (only checking that size > 0 and upload error == 0), writing files to app/tmp/files/ with randomly-generated names. An attacker with any authenticated account, including read-only roles, can exploit this to perform repeated uploads and exhaust server disk space. The impact is limited to disk consumption; files are stored outside the web root, receive random names preventing traversal, and are not directly served over HTTP, ruling out RCE, XSS, or arbitrary file overwrite. The fix restricts the ACL requirement from "*" to "perm_add" to align with neighboring template-management actions.

Affected products

  • MISP MISP ≤2.5.45

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fix applied via commit 8e88859

References

Related threats