s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-94393

📛 CVE Title

MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport

Description

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report’s UUID. Once moved, they could view and change information that they were not originally allowed to access. The vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID. The main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISP’s normal access restrictions. Version affected: <2.5.47

Overview

State
PUBLISHED
Assigner (CNA)
CIRCL
CVSS severity
MEDIUM
CVSS score
CVSS 6.4 / 10 6.4 6.4 / 10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Effective score
6.4 / 10 MEDIUM source: CNA overview
CWE(s)
CWE-639, CWE-284
Reserved
2026-09-21
Published
2026-09-21 13:14 UTC
Last updated
2026-09-21 15:18 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94393.json

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-21 14:17:30 UTC
NVD last modified
2026-09-21 16:17:30 UTC

NVD / KEV / EPSS data refreshed 2026-09-22 03:00 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-83911
Assigner
CIRCL
Published
Sep 21, 2026, 1:14:00 PM
Updated
Sep 21, 2026, 3:18:17 PM
EUVD base score (CVSS 4.0)
6.4 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
EUVD-reported EPSS
0.0000
Vendors
MISP
Products
MISP (0 <2.5.47)
Aliases
GHSA-rq8q-gvp5-cmqp

ENISA description: When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report’s UUID. Once moved, they could view and change information that they were not originally allowed to access. The vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID. The main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISP’s normal access restrictions. Version affected: <2.5.47

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
MISP MISP 0 (affected) —

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (1)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

  • web:basefortify.eu

    Hi! I'm here to help you understand CVE-2026-94393 . Ask me anything about the vulnerability, its impact, or mitigation strategies.

    2026-09-22 17:07 UTC
  • web:cvefeed.io

    The following list is the news that have been mention CVE-2026-94393 vulnerability anywhere in the article. Results are limited to the first 20 news articles due to potential performance issues. EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

    2026-09-22 17:07 UTC
  • web:cvetodo.com

    CVE-2026-94393 is a CVSS 6.4 medium-severity vulnerability in MISP. Full technical analysis, mitigations , and exploit status — updated in real time.

    2026-09-22 17:07 UTC
  • web:feedly.com

    CVE ID : CVE-2026-94393 Published : Sept. 21, 2026 , 1:14 p.m. 35 minutes ago Description : When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event.

    2026-09-22 17:07 UTC
  • web:sec.cloudapps.cisco.com

    On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...

    2026-09-22 17:07 UTC
  • web:senserva.com

    Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.

    2026-09-22 17:07 UTC
  • web:www.cvefind.com

    Full details for CVE-2026-94393 : technical description, impact, CVSS/EPSS scores, linked CWE, CAPEC, affected CPEs, disclosure date, and mitigation options.

    2026-09-22 17:07 UTC
  • web:www.outfaze.com

    MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own ...

    2026-09-22 17:07 UTC
  • web:www.rapid7.com

    CVE-2026-94393 : MISP: When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without…. View severity, references, and remediation details from Rapid7.

    2026-09-22 17:07 UTC
  • web:www.tenable.com

    When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report's UUID. Once moved, they could ...

    2026-09-22 17:07 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-94393.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-94393",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-21T15:18:01.147790Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-21T15:18:17.855Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "modules": [
            "app/Model/EventReport.php"
          ],
          "product": "MISP",
          "programFiles": [
            "app/Model/EventReport.php"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.47",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 4.8"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "David Andr\u00e9"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "Jeroen Pinoy"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<div></div><p>When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event.</p><p>As a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report\u2019s UUID. Once moved, they could view and change information that they were not originally allowed to access.</p><p>The vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID.</p><p>The main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISP\u2019s normal access restrictions.</p><p>Version affected: &lt;2.5.47</p><div></div>"
            }
          ],
          "value": "When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event.\n\nAs a result, a user who has editing rights on one event could potentially move a report from another event into their own event, as long as they know or can guess the report\u2019s UUID. Once moved, they could view and change information that they were not originally allowed to access.\n\nThe vulnerability requires the attacker to have editor access to at least one event and to know or discover a valid report UUID.\n\nThe main impact is that private event reports could be exposed or modified across event boundaries, bypassing MISP\u2019s normal access restrictions.\n\nVersion affected: <2.5.47"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-174",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-174 Exploiting Incorrectly Handled Edge Cases"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-639",
              "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-284",
              "description": "CWE-284 Improper Access Control",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-21T13:14:00.619Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/43665b9bb"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<p>The fix adds an ownership check in editReport: before adopting an existing report found by UUID, the code now verifies that the report's event_id matches the event being edited. If the UUID resolves to a report belonging to a different event, the operation is rejected with an error message, preventing cross-event reparenting, unauthorized read, and unauthorized overwrite of reports.</p>"
            }
          ],
          "value": "The fix adds an ownership check in editReport: before adopting an existing report found by UUID, the code now verifies that the report's event_id matches the event being edited. If the UUID resolves to a report belonging to a different event, the operation is rejected with an error message, preventing cross-event reparenting, unauthorized read, and unauthorized overwrite of reports."
        }
      ],
      "title": "MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "review",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The affected version range is inferred from the tag_version_boundary (v2.5.47, 56 commits after fix); the exact first affected and first fixed release versions are not stated in the patch and are marked unspecified.",
                  "PR:L assumes the attacker needs at minimum editor-level access to one event; the patch does not specify whether viewer-level access could also trigger the code path, but the commit message explicitly references 'an event editor'.",
                  "CAPEC-174 is selected as the closest available attack pattern; no CAPEC entry specifically covers IDOR or broken object reference resolution, so the mapping is approximate.",
                  "The CVSS sub-component impact (SC:H, SI:H) assumes the event report data constitutes a distinct data asset whose confidentiality and integrity are the primary impact, rather than the MISP application's own state.",
                  "The commit date (2026-09-16) and tag boundary are taken at face value from the supplied metadata; no independent verification of release timing was performed."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-174",
                    "rationale": "The edge case of a UUID belonging to a different event was not handled: the code assumed any UUID found in the global table belonged to the current event. The attacker exploits this unhandled edge case to reparent a foreign report. This is the closest CAPEC; a more specific 'IDOR' or 'broken object reference' CAPEC does not exist in the CAPEC catalog, so CAPEC-174 is the best available match."
                  }
                ],
                "commit": "43665b9bb6bd39af0db1f38e608bdf2cb84b9dec",
                "confidence": "medium",
                "credits": [
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 4.8"
                  },
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "David Andr\u00e9"
                  },
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Jeroen Pinoy"
                  }
                ],
                "cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: the attacker only needs to supply a known/guessed UUID in a standard edit request; no race or complex condition. AT:N: no manipulation of the target environment is required. PR:L: the attacker must be an authenticated user with editor role on at least one event. UI:N: no victim interaction is needed. VC:N/VI:N/VA:N: the MISP application itself (its configuration, credentials, availability) is not directly impacted. SC:H: the attacker gains read access to private report data in events they cannot otherwise see. SI:H: the attacker can overwrite and modify report data belonging to other events. SA:N: no safety-system impact.",
                "fixSummary": "The fix adds an ownership check in editReport: before adopting an existing report found by UUID, the code now verifies that the report's event_id matches the event being edited. If the UUID resolves to a report belonging to a different event, the operation is rejected with an error message, preventing cross-event reparenting, unauthorized read, and unauthorized overwrite of reports.",
                "generatedAt": "2026-09-21T13:01:16.364280Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 9,
                      "assumptionCount": 5,
                      "confidence": "medium",
                      "model": "qwen3.8:27b",
                      "score": 5
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "2306bd95d16b9c00582997897aa9181253364082a09589640fce576a03beafb4",
                "patchSummary": "In app/Model/EventReport.php, the editReport method's else-branch (handling an existing report found by UUID) now includes an 11-line guard: it compares (string)$existingReport['EventReport']['event_id'] against (string)$eventId and, on mismatch, appends an error string and returns early, preventing the subsequent assignment of the foreign report's ID to the current event's report record.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "43665b9bb6bd39af0db1f38e608bdf2cb84b9dec",
                    "patchSha256": "2306bd95d16b9c00582997897aa9181253364082a09589640fce576a03beafb4",
                    "source": "https://github.com/MISP/MISP/commit/43665b9bb.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/43665b9bb.patch",
                    "subject": "fix: [security] Refuse to adopt an event report that belongs"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/43665b9bb.patch",
                "subject": "fix: [security] Refuse to adopt an event report that belongs",
                "tagVersionBoundary": {
                  "commits_after_fix": 56,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.47",
                  "version": "2.5.47",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-639",
                    "rationale": "The report UUID is a user-controlled key resolved globally without scoping to the caller's event context. The system failed to verify that the referenced object (report) belongs to the event the caller is authorized to edit, allowing cross-event access."
                  },
                  {
                    "cweId": "CWE-284",
                    "rationale": "The broader category applies: MISP's per-event access control model was bypassed because the editReport path did not enforce that a report UUID maps to the same event the caller is operating on."
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20057"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-94393",
    "datePublished": "2026-09-21T13:14:00.619Z",
    "dateReserved": "2026-09-21T13:13:54.299Z",
    "dateUpdated": "2026-09-21T15:18:17.855Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}