Executive brief
MISP is an open-source threat intelligence platform used by organizations to share and analyze security information. A vulnerability allows users holding read-only API keys to bypass access restrictions and regain their full account permissions, potentially enabling unauthorized data modification, deletion, or administrative actions. An attacker with a valid read-only API key can exploit this with a single request to a specific MISP function.
Technical details
The vulnerability exists in MISP's API key permission enforcement, where read-only API keys fail to properly restrict role elevation. An authenticated attacker with a read-only API key can trigger an account restoration function that inadvertently restores the underlying user account's full permissions, including write and delete capabilities. A single unauthenticated HTTP request to the affected endpoint is sufficient to exploit this issue; no additional user interaction is required.
Affected products
- MISP Project MISP before 2.5.47
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in commit fd27e59