Junglewise Threat Intelligence

CVE-2026-94393: MISP event report access control bypass via UUID

CVE-2026-94393 · Severity: info · Published 2026-09-21

Technologies: Misp. Vendors: Misp.

Executive brief

MISP, an open-source threat intelligence platform, contains a flaw that allows event editors to move reports between events without proper authorization checks. An attacker with editing rights on any event could potentially steal or modify confidential reports from other events by guessing or discovering their UUID, bypassing MISP's access controls. The vulnerability affects all versions prior to 2.5.47 and requires the attacker to have editor access to at least one event.

Technical details

MISP's editReport function resolves event reports globally by UUID without verifying that the report belongs to the event being edited, allowing an event editor to reparent reports across event boundaries. The vulnerability is an authorization bypass in the EventReport model where nested event reports are adopted without checking event ownership. The fix adds validation to reject UUIDs that already belong to a different event.

Affected products

  • MISP MISP prior to 2.5.47

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in commit 43665b9

References

Related threats