Executive brief
MISP is an open-source threat intelligence platform used by organizations to share and collaborate on security data. A vulnerability in the dashboard template listing allowed authenticated users to retrieve email addresses of template owners via the REST API, even when they lacked permission to see them in the normal web interface. This could expose sensitive contact information to lower-privileged users within an organization.
Technical details
The vulnerability is an information disclosure (CWE-863: Incorrect Authorization) in MISP's DashboardsController::listTemplates() method. The code fetched User.email addresses unconditionally from the database but only redacted them in the HTML rendering path via afterFind(). Authenticated users requesting the REST/JSON endpoint bypassed this redaction, receiving template owner emails without the intended privilege check. The root cause was conflating rendering mode (_isRest()) with authorization policy. The fix centralizes the authorization decision in a User::canSeeEmails() helper that checks if the requester is a site admin or if Security.disclose_user_emails is explicitly enabled, and only fetches email addresses when the check passes.
Affected products
- MISP Project MISP ≤2.5.45
Timeline
- 2026-09-07: disclosed: CVE-2026-86417 published
- 2026-08-26: patched: Fix committed to MISP repository