← Vulnerability feed

Vulnerability record · CVE-2026-10855 · published 4 June 2026

CVE-2026-10855: Misp-project misp missing authorization vulnerability

Misp Project · Misp

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existing template. As a result, an authenticated user with access to the template import functionality could forcibly overwrite an event template owned by another organization. Successful exploitation could allow unauthorized modification of another organization’s event template, potentially altering template structure, attributes, or metadata used for subsequent event creation or sharing workflows. Site administrators are not affected by this restriction, as they are explicitly allowed to overwrite templates across organizations. The issue was fixed by enforcing an ownership check before overwrite: non-site-admin users may only overwrite templates owned by their own organization.

5.1 CVSS 4.0 Medium EPSS 0.15% · top 96.0% CWE-862 · Missing authorization
5.1CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existing template. As a result, an authenticated user with access to the template import functionality could forcibly overwrite an event template owned by another organization. Successful exploitation could allow unauthorized modification of another organization’s event template, potentially altering template structure, attributes, or metadata used for subsequent event creation or sharing workflows. Site administrators are not affected by this restriction, as they are explicitly allowed to overwrite templates across organizations. The issue was fixed by enforcing an ownership check before overwrite: non-site-admin users may only overwrite templates owned by their own organization.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-10855 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-29858Misp-project misp vulnerabilityIn MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.EPSS 0.38%9.8CVE-2024-29859Misp-project misp unrestricted file upload vulnerabilityIn MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.EPSS 0.82%9.8CVE-2024-25674Misp-project misp unrestricted file upload vulnerabilityAn issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.EPSS 0.78%9.8CVE-2024-25675Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Cont…EPSS 0.82%9.8CVE-2023-50918Misp-project misp vulnerabilityapp/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.EPSS 0.79%9.8CVE-2023-48659Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.EPSS 0.92%9.8CVE-2023-48657Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.EPSS 0.92%9.8CVE-2023-48655Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2026-10855), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.