CVE-2026-95697
📛 CVE Title
MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata
Description
MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions. According to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance. The vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CIRCL
- CVSS severity
- MEDIUM
- CVSS score
- 5.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N- Effective score
- 5.3 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-862 - Reserved
- 2026-09-22
- Published
- 2026-09-22 14:31 UTC
- Last updated
- 2026-09-22 15:06 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95697.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 15:17:27 UTC
- NVD last modified
- 2026-09-22 16:18:23 UTC
NVD / KEV / EPSS data refreshed 2026-09-23 02:29 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84494 - Assigner
- CIRCL
- Published
- Sep 22, 2026, 2:31:25 PM
- Updated
- Sep 22, 2026, 3:06:43 PM
- EUVD base score (CVSS 4.0)
-
5.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- MISP
- Products
-
MISP (0 <2.5.47)
- Aliases
-
GHSA-prf9-8cgh-75pc
ENISA description: MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions. According to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance. The vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MISP | MISP |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security patch patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/MISP/MISP/commit/f3ec974ee 5a6e4751-2f3f-4070-9419-94fb35b644e8
Remediations (10)
-
web:catalog.update.microsoft.com
Welcome to the Microsoft Update Catalog site. We want your feedback! Visit our newsgroup or send us an email to provide us with your thoughts and suggestions. To get started using the site, enter in your search terms in the Search box above or visit our FAQ for search tips. |Newsgroup|Send us your feedback
2026-09-23 15:40 UTC -
web:cvefeed.io
The following list is the news that have been mention CVE-2026-95697 vulnerability anywhere in the article. Results are limited to the first 20 news articles due to potential performance issues. EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.
2026-09-23 15:40 UTC -
web:feedly.com
In MISP (Organisation component) up to version 2.5.46, remote attackers can manipulate the argument `force` to trigger improper privilege management.
2026-09-23 15:40 UTC -
web:fixitphill.com
Patch Microsoft Exchange CVE - 2026 -42897 with June 2026 security updates, keep EEMS mitigations during rollout, and verify OWA and mail flow.
2026-09-23 15:40 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:40 UTC -
web:support.microsoft.com
Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home. (See What version of Office am I using?) How to get and install the update Method 1: Microsoft Update This update is available from Microsoft Update. When you turn on ...
2026-09-23 15:40 UTC -
web:vulmon.com
MISP Authorization Flaw Enables Organization Metadata Tampering by SG Editors. An authorization flaw in MISP's Organisation model captureOrg method allows users…
2026-09-23 15:40 UTC -
web:vulners.com
CVE-2026-95697 🗓️ 22 Sep 2026 07:31:25 Reported by CIRCL Type cve 🔗 web.nvd.nist.gov 👁 2 Views
2026-09-23 15:40 UTC -
web:windowsforum.com
Microsoft's Fastest Fix Is a Mitigation , Not a Patch The important detail in Microsoft's May 14 notice is that there is no permanent Exchange security update available yet for CVE - 2026 -42897. Microsoft says it is working on one and will release it later for affected supported paths, but today's defensive action is mitigation .
2026-09-23 15:40 UTC -
web:www.techtimes.com
Exchange Server OWA Zero-Day CVE - 2026 -42897 Exploited With No Permanent Patch and New Mitigation Gaps Microsoft's emergency fix for on-premises Exchange breaks OWA calendar printing and leaves ...
2026-09-23 15:40 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-95697.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95697",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:06:23.172470Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:06:43.859Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"Organisation model (app/Model/Organisation.php)"
],
"product": "MISP",
"programFiles": [
"app/Model/Organisation.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions.</p><p>According to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance. </p><p>The vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records.</p>"
}
],
"value": "MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger this code path, allowing them to modify organization metadata that should be restricted to site administrators or users with sync permissions.\n\nAccording to the commit message, this could lead to blueprint-based sharing group manipulation, meaning an attacker with SG editor access could alter organizational attributes in ways that influence how sharing groups and blueprints behave across the MISP instance.\u00a0\n\nThe vulnerability requires an authenticated user with at least SG editor privileges and network access to the MISP web interface. The impact is primarily on the integrity of organization records and, potentially, on the integrity of sharing group configurations derived from those records."
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:31:25.876Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/f3ec974ee"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap.</p>"
}
],
"value": "The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap."
}
],
"title": "MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary is inferred from the tag_version_boundary metadata (v2.5.47, 139 commits after fix), suggesting the fix landed in or before v2.5.47. The exact first affected version is not specified in the patch.",
"The 'blueprint based SG manipulation' impact mentioned in the commit message is taken at face value for the SI:H rating; the patch itself only shows the org metadata overwrite fix and does not include code demonstrating the SG manipulation path.",
"CAPEC-100 (Parameter Tampering) is the closest available mapping; the vulnerability is more precisely a missing authorization check (CWE-862) than a classic parameter tampering scenario, but no CAPEC entry directly models 'authenticated user exploits missing permission gate via a boolean flag.'",
"The PR:L rating assumes that SG editor is a low-privilege role in MISP's permission hierarchy; the patch references perm_site_admin and perm_sync as the required higher-level permissions, implying SG editor is below that level.",
"No specific MISP version range is confirmed beyond the v2.5.47 tag boundary; earlier versions may or may not be affected depending on when the captureOrg method was introduced."
],
"capecRationale": [
{
"capecId": "CAPEC-100",
"rationale": "The closest plausible CAPEC is Parameter Tampering: an authenticated user with a lower-privilege role (SG editor) invokes the captureOrg function with the $force parameter set to true, triggering a code path that was intended only for higher-privilege users. The user manipulates a function parameter to cause unintended privileged behavior. This mapping is approximate because the core issue is a missing authorization check rather than classic parameter tampering, but no CAPEC entry more precisely describes an authenticated user exploiting a missing permission gate via a boolean flag."
}
],
"commit": "f3ec974ee2d72d77311dbb364c70f1aee83a58c2",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: The attack requires only calling the existing captureOrg function with $force=true; no race conditions or complex bypasses are needed. AT:N: No user interaction or attack tooling beyond normal API usage is required. PR:L: The attacker needs an authenticated account with at least SG editor privileges, which is a low-privilege role in MISP. UI:N: No victim interaction is required. VC:N: No confidentiality impact is evident from the patch. VI:H: Organization metadata (type, nationality, sector, contacts, dates) can be arbitrarily modified, representing high integrity impact on the vulnerable component. VA:N: No availability impact. SC:N: No direct confidentiality impact on other systems. SI:H: The commit message explicitly notes the issue 'could lead to blueprint based SG manipulation,' indicating integrity impact extends to sharing group configurations in the broader MISP ecosystem. SA:N: No availability impact on other systems.",
"fixSummary": "The fix adds an authorization check to the captureOrg method so that the forced overwrite of organization metadata fields is only permitted when the invoking user holds either the site_admin permission or the sync permission. This ensures that low-privilege roles such as sharing group editors can no longer trigger the metadata overwrite path, closing the authorization gap.",
"generatedAt": "2026-09-22T14:23:51.691782Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "63108ba85f58bd5ec8318ea052879e536aaa83464f8ff4f90ef1d386913dc835",
"patchSummary": "In app/Model/Organisation.php, the condition guarding the forced overwrite of organization metadata fields (type, date_created, date_modified, nationality, sector, contacts) was changed from a simple 'if ($force)' check to 'if ($force && (!empty($user['Role']['perm_site_admin']) || !empty($user['Role']['perm_sync'])))'. This one-line change adds a role-based authorization requirement so that only site administrators or sync-permitted users can execute the metadata overwrite when $force is true.",
"patchTruncated": false,
"patches": [
{
"commit": "f3ec974ee2d72d77311dbb364c70f1aee83a58c2",
"patchSha256": "63108ba85f58bd5ec8318ea052879e536aaa83464f8ff4f90ef1d386913dc835",
"source": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"subject": "fix: [security] overwrite of org metadata by sg editors"
}
],
"source": "https://github.com/MISP/MISP/commit/f3ec974ee.patch",
"subject": "fix: [security] overwrite of org metadata by sg editors",
"tagVersionBoundary": {
"commits_after_fix": 139,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The captureOrg method performed a privileged operation (overwriting organization metadata) based solely on the $force flag without verifying that the authenticated user held the necessary permission (site_admin or sync). The authorization check was entirely absent for this code path, which is the definition of a missing authorization vulnerability."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20182"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95697",
"datePublished": "2026-09-22T14:31:25.876Z",
"dateReserved": "2026-09-22T14:31:23.351Z",
"dateUpdated": "2026-09-22T15:06:43.859Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}