CVE-2026-60124

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-08 14:17

Updated : 2026-07-09 16:29


NVD link : CVE-2026-60124

Mitre link : CVE-2026-60124

CVE.ORG link : CVE-2026-60124


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization