CVE-2026-103858: Misp
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48
Affected products
- Misp Misp: before 2.5.48 (fixed in 2.5.48)
Published 2026-10-01. Last modified 2026-10-01.