Junglewise Threat Intelligence

CVE-2026-88915: MISP event template authorization bypass in sharing group and tagging

CVE-2026-88915 · Severity: info · CVSS 0 · Published 2026-09-10

Technologies: Misp. Vendors: Misp.

Executive brief

MISP is an open-source threat intelligence platform used by organizations to share and collaborate on security events. When users instantiate event templates, the system failed to verify that the user had permission to use the sharing group specified in the template, and incorrectly applied locally-restricted tags globally. An attacker could exploit this to bypass access controls and propagate restricted information beyond intended boundaries.

Technical details

The vulnerability is an authorization bypass in the event template instantiation code path. The template instantiation logic accepted a sharing_group_id from the template definition without calling SharingGroup::canUse() to verify the acting user's permissions, whereas normal event creation did enforce this check. Additionally, the code attached template-specified tags without applying the normal perm_tagger permission checks, and it hardcoded local=>0, causing tags marked local_only to be attached globally and propagate through synchronization and export. The fix adds explicit authorization checks for both sharing groups and tags, and respects the local_only restriction.

Affected products

  • MISP MISP ≤2.5.45

Timeline

  • 2026-09-10: disclosed
  • 2026-08-28: patched

References

Related threats