CVE-2026-103858
Deferred Deferred - Pending Action

Incomplete Authorization Check in MISP Discussion Posts

Vulnerability report for CVE-2026-103858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an authorization flaw in its discussion posting feature. When users post or reply to threads, the system only checked if the thread was restricted to a single organization. It did not verify full access control lists, sharing group membership, or event visibility. This allowed unauthorized users to read thread titles and quoted post content, and even submit new posts to restricted threads.

Detection Guidance

To detect this vulnerability, check MISP version and review discussion thread access logs. Ensure threads are not accessible to unauthorized users by verifying sharing-group membership and event visibility settings. Compare current behavior with the fixed version (>=2.5.48).

Commands: Check MISP version with 'sudo -u www-data ./MISP/app/Console/cake version' or 'grep version /var/www/MISP/app/Config/config.php'. Review logs for unauthorized post attempts in /var/www/MISP/app/tmp/logs/

Impact Analysis

An attacker with authenticated access could access restricted discussion threads they are not authorized to view, read sensitive information in quoted posts, and inject unauthorized content into private discussions. This could lead to data leaks or misinformation within restricted groups.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR's principle of least privilege or HIPAA's safeguards for protected health information. Unauthorized access to restricted discussions may result in data breaches and non-compliance penalties.

Mitigation Strategies

Immediately upgrade MISP to version 2.5.48 or later to apply the security fix. Temporarily restrict discussion thread access to trusted users until upgrade is complete. Review and audit existing threads for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart