PT-2026-42247 · Misp · Misp

Seth Kraft

·

Published

2026-05-20

·

Updated

2026-05-24

·

CVE-2026-9136

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.38
Description An issue exists in the ShadowAttribute proposal creation workflow where the add action accepts user-controlled request data without removing the id field before saving the record. Since the underlying framework interprets a supplied primary key as an instruction to update an existing record, an authenticated user can provide the identifier of an existing ShadowAttribute to update it instead of creating a new proposal. This can lead to unauthorized modification of existing shadow attributes, potentially affecting proposals associated with events the user is not permitted to alter. Depending on the deployment configuration and API responses, this may also expose or move proposal data across event contexts.
Recommendations Update to version 2.5.38.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-9136

Affected Products

Misp