Junglewise Threat Intelligence

CVE-2026-94381: MISP privilege escalation via read-only API key

CVE-2026-94381 · Severity: info · Published 2026-09-21

Technologies: MISP Project MISP. Vendors: MISP Project.

Executive brief

MISP is an open-source threat intelligence platform used by organizations to share and analyze security information. A vulnerability allows users holding read-only API keys to bypass access restrictions and regain their full account permissions, potentially enabling unauthorized data modification, deletion, or administrative actions. An attacker with a valid read-only API key can exploit this with a single request to a specific MISP function.

Technical details

The vulnerability exists in MISP's API key permission enforcement, where read-only API keys fail to properly restrict role elevation. An authenticated attacker with a read-only API key can trigger an account restoration function that inadvertently restores the underlying user account's full permissions, including write and delete capabilities. A single unauthenticated HTTP request to the affected endpoint is sufficient to exploit this issue; no additional user interaction is required.

Affected products

  • MISP Project MISP before 2.5.47

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in commit fd27e59

References

Related threats