PT-2026-42247 · Misp · Misp
Seth Kraft
·
Published
2026-05-20
·
Updated
2026-05-24
·
CVE-2026-9136
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP versions prior to 2.5.38
Description
An issue exists in the ShadowAttribute proposal creation workflow where the add action accepts user-controlled request data without removing the
id field before saving the record. Since the underlying framework interprets a supplied primary key as an instruction to update an existing record, an authenticated user can provide the identifier of an existing ShadowAttribute to update it instead of creating a new proposal. This can lead to unauthorized modification of existing shadow attributes, potentially affecting proposals associated with events the user is not permitted to alter. Depending on the deployment configuration and API responses, this may also expose or move proposal data across event contexts.Recommendations
Update to version 2.5.38.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp