CVE-2026-60124: Misp

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.

Affected products

  • Misp Misp: up to and including 2.5.42

Published 2026-07-08. Last modified 2026-07-09.