PT-2026-40808 · Misp · Misp

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-44380

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.37
Description Improper access control in the authentication key reset functionality allows an authenticated organization administrator to reset authentication keys of site administrator accounts within the same organization. Since non-site administrators are not explicitly restricted from this action, an attacker with organization administrator privileges can obtain a newly generated authentication key for a higher-privileged account to escalate privileges.
Recommendations Update to version 2.5.37.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44380

Affected Products

Misp