← Vulnerability feed

Vulnerability record · CVE-2026-86342 · published 7 September 2026

CVE-2026-86342: Misp-project misp missing authorization vulnerability

Misp Project · Misp

Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls. The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently. Version affected: ≤2.5.45

5.3 CVSS 4.0 Medium EPSS 0.34% · top 74.7% CWE-862 · Missing authorization
5.3CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
9 Sep 2026Last modified by NVD

Description

Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls. The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently. Version affected: ≤2.5.45

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-86342 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-29858Misp-project misp vulnerabilityIn MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.EPSS 0.38%9.8CVE-2024-29859Misp-project misp unrestricted file upload vulnerabilityIn MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.EPSS 0.82%9.8CVE-2024-25674Misp-project misp unrestricted file upload vulnerabilityAn issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.EPSS 0.78%9.8CVE-2024-25675Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Cont…EPSS 0.82%9.8CVE-2023-50918Misp-project misp vulnerabilityapp/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.EPSS 0.79%9.8CVE-2023-48659Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.EPSS 0.92%9.8CVE-2023-48657Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.EPSS 0.92%9.8CVE-2023-48655Misp-project misp vulnerabilityAn issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2026-86342), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.