CVE-2026-103858 PUBLISHED

MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions

Assigner: CIRCL
Reserved: 01.10.2026 Published: 01.10.2026 Updated: 01.10.2026

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.

As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:

  • Read the thread title and the content of the quoted post

  • Submit a new post into the discussion thread

This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).

Affected: <2.5.48

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor MISP
Product MISP
Versions
  • affected from unspecified to 2.5.48 (excl.)

Solutions

The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.

Credits

  • Bastien Bossiroy and Célien Desteucq of NCIA reporter
  • iglocska remediation developer
  • Claude Opus 5.5 (1M context) remediation developer

References

Problem Types

  • CWE-285 Improper Authorization CWE

Impacts

  • CAPEC-10 Parameter Tampering