CVE-2026-95805
📛 CVE Title
MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction
Description
A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses ['theming_enabled'], confirming the intended restriction. The malformed key 'theming_enabled*' does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact). The previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CIRCL
- CVSS severity
- MEDIUM
- CVSS score
- 5.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N- Effective score
- 5.3 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-285 - Reserved
- 2026-09-22
- Published
- 2026-09-22 14:59 UTC
- Last updated
- 2026-09-22 15:53 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95805.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 16:18:24 UTC
- NVD last modified
- 2026-09-22 16:18:24 UTC
NVD / KEV / EPSS data refreshed 2026-09-23 02:29 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84501 - Assigner
- CIRCL
- Published
- Sep 22, 2026, 2:59:22 PM
- Updated
- Sep 22, 2026, 3:53:42 PM
- EUVD base score (CVSS 4.0)
-
5.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- MISP
- Products
-
MISP (0 <2.5.47)
- Aliases
-
GHSA-c2r5-m9w2-228q
ENISA description: A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses ['theming_enabled'], confirming the intended restriction. The malformed key 'theming_enabled*' does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact). The previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MISP | MISP |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security patch patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/MISP/MISP/commit/5ac8d1e4d 5a6e4751-2f3f-4070-9419-94fb35b644e8
Remediations (10)
-
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the Microsoft security update that addresses CVE - 2026 -20805 from the Microsoft Security Update Guide or Windows Update. Reboot the system after installing the patch to ensure the Desktop Window Manager component is reinitialized with the patched binary.
2026-09-23 15:40 UTC -
web:blog.qualys.com
With Qualys Policy Audit's out-of-the-box mitigation or Compensatory Controls, which reduce the risk of a vulnerability being exploited because the remediation ( fix / patch ) cannot be done immediately, these security controls are not recommended by any industry standards, such as CIS and DISA-STIG.
2026-09-23 15:40 UTC -
web:krebsonsecurity.com
This entry was posted on Tuesday 13th of January 2026 07:47 PM Latest Warnings The Coming Storm Time to Patch
2026-09-23 15:40 UTC -
web:learn.microsoft.com
In this library you will find the following security documents that have been released by the Microsoft Security Response Center (MSRC). The MSRC investigates all reports of security vulnerabilities affecting Microsoft products and services, and releases these documents as part of the ongoing effort to help you manage security risks and help keep your systems protected. Please use the ...
2026-09-23 15:40 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:40 UTC -
web:socprime.com
CVE - 2026 -20805 Analysis Microsoft's January 2026 Patch Tuesday release delivers fixes for 112 security vulnerabilities spanning a wide range of products, including Windows, Office, Azure, Edge, SharePoint, SQL Server, SMB, and Windows management services.
2026-09-23 15:40 UTC -
web:support.microsoft.com
This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5121768) is cumulative. It includes all improvements from previous security and non-security updates, along with an additional fix . Improvements This OOB update includes the following improvement: [System Performance] This update addresses an issue affecting a limited number of devices with an Intel ...
2026-09-23 15:40 UTC -
web:www.cvefind.com
Full details for CVE-2026-95805 : technical description, impact, CVSS/EPSS scores, linked CWE, CAPEC, affected CPEs, disclosure date, and mitigation options.
2026-09-23 15:40 UTC -
web:www.lansweeper.com
Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday January 2026 summary.
2026-09-23 15:40 UTC -
web:www.rapid7.com
CVE-2026-95805 : MISP: A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action…. View severity, references, and remediation details from Rapid7.
2026-09-23 15:40 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-95805.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95805",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:53:31.726592Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:53:42.092Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"ACLComponent"
],
"product": "MISP",
"programFiles": [
"app/Controller/Component/ACLComponent.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "Thomas Lacroix"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses ['theming_enabled'], confirming the intended restriction. The malformed key 'theming_enabled*' does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact). </p><p>The previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access.</p>"
}
],
"value": "A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array values define which role or permission grants access to a given controller action. The adjacent entry previewEventObjects correctly uses ['theming_enabled'], confirming the intended restriction. The malformed key 'theming_enabled*' does not match any valid permission identifier, causing the access control check for previewEventAttributes to malfunction. Depending on the ACL evaluation logic, this could result in either unauthorized users gaining access to the previewEventAttributes endpoint (authorization bypass) or legitimate users being denied access (availability impact).\u00a0\n\nThe previewEventAttributes endpoint exposes event attribute data within MISP so an authorization bypass could expose sensitive indicator and attribute data to users who should not have access."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Forced Browsing"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:59:22.041Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/5ac8d1e4d"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string 'theming_enabled*' to the correct 'theming_enabled', restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry.</p>"
}
],
"value": "The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string 'theming_enabled*' to the correct 'theming_enabled', restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry."
}
],
"title": "MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact ACL evaluation behavior when a permission string does not match any valid role (default-deny vs. default-allow) is not visible in the patch; the CVSS assumes the more security-relevant interpretation (authorization bypass) but a denial-of-service interpretation is also possible.",
"The affected version range is inferred from the tag boundary v2.5.47 (227 commits after the fix); the exact first affected version is not stated in the patch.",
"The CAPEC-126 mapping is the closest available pattern; the actual attack is a configuration typo rather than an active browsing technique, so the mapping is approximate.",
"The security impact is assumed to be limited to the previewEventAttributes endpoint; no evidence in the patch suggests other endpoints or data stores are affected.",
"The CVSS assumes the endpoint exposes event attribute data viewable by unauthorized users; the actual data sensitivity depends on MISP deployment configuration."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The closest plausible attack pattern is Forced Browsing, where an attacker accesses a resource (the previewEventAttributes endpoint) that should be restricted by the ACL. The typo in the ACL key may cause the authorization check to fail to deny access, effectively allowing a user without the theming_enabled permission to reach the endpoint. Uncertainty: the exact ACL evaluation behavior on a non-matching rule (default-deny vs. default-allow) is not visible in the patch, so it is also possible the typo causes a denial rather than a bypass. CAPEC-126 is selected as the best available match for an access-control bypass via misconfiguration."
}
],
"commit": "5ac8d1e4dea72f71bec3789350b748f0ad21c42c",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "remediation developer",
"value": "Thomas Lacroix"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: The vulnerability is a static typo in configuration; no race or complex condition is needed. AT:N: No attack target manipulation required. PR:L: The attacker must be an authenticated MISP user to reach the endpoint. UI:N: No victim interaction needed. VC:L: If the ACL bypass is confirmed, an unauthorized user could view event attribute data (limited confidentiality impact). VI:N and VA:N: No integrity or availability impact is evident from the patch. SC/SI/SA:N: No secondary system impact. The overall severity is Low, reflecting a single-endpoint access control misconfiguration with limited data exposure.",
"fixSummary": "The fix corrects the ACL permission key for the previewEventAttributes action from the malformed string 'theming_enabled*' to the correct 'theming_enabled', restoring the intended access control restriction so that only users holding the theming_enabled permission can invoke the endpoint, consistent with the adjacent previewEventObjects entry.",
"generatedAt": "2026-09-22T14:55:18.958107Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "c102952ebfaba16a0d028044d1bc0ab063381442b99de01bfc592144f2de9cc5",
"patchSummary": "In app/Controller/Component/ACLComponent.php (line 473), the ACL array value for the 'previewEventAttributes' key was changed from ['theming_enabled*'] to ['theming_enabled'], removing the erroneous trailing asterisk that made the permission string non-matching. One line changed, one insertion, one deletion.",
"patchTruncated": false,
"patches": [
{
"commit": "5ac8d1e4dea72f71bec3789350b748f0ad21c42c",
"patchSha256": "c102952ebfaba16a0d028044d1bc0ab063381442b99de01bfc592144f2de9cc5",
"source": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"subject": "fix: [ACL] typo in previewEventAttributes key"
}
],
"source": "https://github.com/MISP/MISP/commit/5ac8d1e4d.patch",
"subject": "fix: [ACL] typo in previewEventAttributes key",
"tagVersionBoundary": {
"commits_after_fix": 227,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-285",
"rationale": "The ACL rule for previewEventAttributes contained a typo ('theming_enabled*') that prevented the authorization check from matching the intended permission, causing the access control mechanism to not enforce the restriction as designed. This is a direct failure of the authorization logic due to a misconfigured rule."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20240"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-95805",
"datePublished": "2026-09-22T14:59:22.041Z",
"dateReserved": "2026-09-22T14:59:19.797Z",
"dateUpdated": "2026-09-22T15:53:42.092Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}