CVE-2026-94381
Deferred Deferred - Pending Action

MISP API Key Permission Bypass Vulnerability

Vulnerability report for CVE-2026-94381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: CIRCL

Description

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidentally restore the user’s normal account permissions. This means someone with a read-only API key could potentially gain write, delete, or even administrator access if their underlying account has those permissions. Exploiting the issue requires a valid read-only API key and a single request to the affected function. The main impact is that MISP’s API key restrictions can be bypassed, allowing actions that the API key was specifically meant to prevent. Version affected: <2.5.47

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.47 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MISP allows a user with a read-only API key to gain elevated permissions such as write, delete, or administrator access. Normally, a read-only key should only allow viewing data, but a specific function incorrectly restores the user's full account permissions after login.

Detection Guidance

To detect this vulnerability, check if your MISP instance is running a version older than 2.5.47. Use commands like 'misp --version' or inspect the version in the web interface. Verify API key permissions by reviewing user roles and API key restrictions in the admin panel.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to perform actions beyond their intended access level. Attackers with a read-only API key could modify, delete, or gain administrative control over MISP data, potentially leading to data breaches or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating compliance requirements for data protection such as GDPR or HIPAA. It undermines access control measures, potentially resulting in legal penalties or loss of trust.

Mitigation Strategies

Immediately update MISP to version 2.5.47 or later. Review all API keys and ensure read-only keys are properly restricted. Monitor for unauthorized access or privilege escalation attempts in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart