MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.

As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:

- Read the thread title and the content of the quoted post

- Submit a new post into the discussion thread

This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).

Affected: <2.5.48

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility. As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could: - Read the thread title and the content of the quoted post - Submit a new post into the discussion thread This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in). Affected: <2.5.48
Title MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-01T11:31:32.840Z

Reserved: 2026-10-01T11:31:31.101Z

Link: CVE-2026-103858

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses