Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path.
The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different sharing_group_id, that authorization branch was skipped. Later, MISP’s field-recovery logic restored the existing event distribution from storage. For events already configured with sharing-group distribution, the unauthorized sharing-group ID could therefore be saved.
The fix adds authorization checks in both the controller and Event::_edit() whenever a non-empty sharing_group_id is supplied without distribution. The model now calls SharingGroup::checkIfAuthorised() before persisting the change.
Version affected: ≤2.5.45
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/cf3ee4026 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 09:16
Updated : 2026-09-16 13:42
NVD link : CVE-2026-91825
Mitre link : CVE-2026-91825
CVE.ORG link : CVE-2026-91825
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
