PT-2026-42247 · Misp · Misp

·

CVE-2026-9136

·

Published

2026-05-20

·

Updated

2026-05-24

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MISP versions prior to 2.5.38
Description An issue exists in the ShadowAttribute proposal creation workflow where the add action accepts user-controlled request data without removing the id field before saving the record. Since the underlying framework interprets a supplied primary key as an instruction to update an existing record, an authenticated user can provide the identifier of an existing ShadowAttribute to update it instead of creating a new proposal. This can lead to unauthorized modification of existing shadow attributes, potentially affecting proposals associated with events the user is not permitted to alter. Depending on the deployment configuration and API responses, this may also expose or move proposal data across event contexts.
Recommendations Update to version 2.5.38.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9136

Affected Products

Misp