PT-2026-40808 · Misp · Misp
Published
2026-05-13
·
Updated
2026-05-13
·
CVE-2026-44380
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.37
Description
Improper access control in the authentication key reset functionality allows an authenticated organization administrator to reset authentication keys of site administrator accounts within the same organization. Since non-site administrators are not explicitly restricted from this action, an attacker with organization administrator privileges can obtain a newly generated authentication key for a higher-privileged account to escalate privileges.
Recommendations
Update to version 2.5.37.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp