Executive brief
MISP is an open-source threat intelligence platform used to share and correlate threat information across organizations. Certain dashboard widgets failed to enforce visibility restrictions, allowing authenticated users to enumerate all organizations in the system and access sensitive organization data even when the administrator had intentionally hidden this information. This could expose the complete organizational directory to unauthorized internal users.
Technical details
Multiple MISP dashboard widgets ignored the Security.hide_organisation_index_from_users configuration setting, allowing authenticated users without the perm_sharing_group permission to enumerate organizations through inconsistent authorization checks. The vulnerabilities included: (1) organisation index widgets returning full organisation names and IDs, (2) unrestricted database queries accepting limit=0 or negative values to bypass result limits and fetch entire organization tables, and (3) an organization contribution leaderboard that counted Event.orgc_id across all events without authorization scoping, revealing every organization regardless of whether the user could access related events. The attack requires only valid authentication; no special privileges are needed to trigger the enumeration. Patches were released to add permission checks in affected widgets and withdraw the leaderboard widget for restricted users.
Affected products
- MISP MISP ≤2.5.45
Timeline
- 2026-09-07: disclosed: Published in NVD
- 2026-08-28: patched: Fixes committed to repository