Executive brief
MISP, an open-source threat intelligence platform, contained a configuration typo in its access control rules that could allow unauthorized users to view event attribute data. The misconfigured permission check on the previewEventAttributes endpoint may result in sensitive indicator and attribute information being exposed to users who should not have access to it.
Technical details
A malformed ACL permission key 'theming_enabled*' (with trailing asterisk) in the ACLComponent fails to match any valid permission identifier, causing the access control check for the previewEventAttributes action to bypass authorization. An attacker with network access to the MISP instance could exploit this to view restricted event attribute data. The fix changes the permission key to the correct 'theming_enabled' to restore proper authorization enforcement.
Affected products
- MISP MISP
Timeline
- 2026-09-22: disclosed
- 2026-09-22: patched