Executive brief
MISP's dashboard organisation picker exposed hidden organisation metadata to authenticated users, bypassing visibility restrictions that should have applied. An attacker with valid credentials could discover the names and identifiers of organisations that their account should not have access to, potentially compromising operational security in threat intelligence sharing environments.
Technical details
The vulnerability is an information disclosure weakness in the dashboard organisation picker endpoint. The vulnerable component failed to apply the same ACL (access control list) conditions enforced by the normal organisation index and per-organisation view endpoints. When the Security.hide_organisation_index_from_users configuration was enabled, the picker would still query and return all organisations in the system, exposing organisation ID, UUID, and name fields. Authenticated users could leverage this to enumerate hidden organisations. The fix applies Organisation::createConditions() to append proper ACL restrictions to the picker query, scoping results to organisations associated with visible events/proposals plus the user's own organisation.
Affected products
- MISP Project MISP ≤2.5.45
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fix committed to repository (8ca4486)