CVE-2026-94374
📛 CVE Title
MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports
Description
MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute and object processing loops, the report loop did not unset the client-supplied 'id' field before calling save(). Because the MISP EventReport model's create() method does not strip the id field, an authenticated user with permission to submit module results could include an 'id' value referencing an existing report belonging to a different event. Upon save(), the ORM would update that existing row rather than insert a new one, allowing the attacker to - read the content of another event's report by reparenting it into their own event - overwrite the report's fields with attacker-controlled data - change the report's event_id to redirect ownership. This constitutes an authorization bypass through a user-controlled key, enabling cross-event data disclosure and integrity compromise. The vulnerability requires an authenticated session with the ability to invoke module result processing on an event. Version affected: <2.5.47
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CIRCL
- CVSS severity
- HIGH
- CVSS score
- 8.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N- Effective score
- 8.3 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-639,CWE-472 - Reserved
- 2026-09-21
- Published
- 2026-09-21 12:25 UTC
- Last updated
- 2026-09-21 15:21 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94374.json
- Linked Threat
- CVE-2026-94374 — MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-21 13:17:12 UTC
- NVD last modified
- 2026-09-21 16:17:30 UTC
NVD / KEV / EPSS data refreshed 2026-09-22 03:10 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-83904 - Assigner
- CIRCL
- Published
- Sep 21, 2026, 12:25:02 PM
- Updated
- Sep 21, 2026, 3:21:57 PM
- EUVD base score (CVSS 4.0)
-
8.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- MISP
- Products
-
MISP (0 <2.5.47)
- Aliases
-
GHSA-qg5m-5m7w-mf5x
ENISA description: MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute and object processing loops, the report loop did not unset the client-supplied 'id' field before calling save(). Because the MISP EventReport model's create() method does not strip the id field, an authenticated user with permission to submit module results could include an 'id' value referencing an existing report belonging to a different event. Upon save(), the ORM would update that existing row rather than insert a new one, allowing the attacker to - read the content of another event's report by reparenting it into their own event - overwrite the report's fields with attacker-controlled data - change the report's event_id to redirect ownership. This constitutes an authorization bypass through a user-controlled key, enabling cross-event data disclosure and integrity compromise. The vulnerability requires an authenticated session with the ability to invoke module result processing on an event. Version affected: <2.5.47
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MISP | MISP |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security patch patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/MISP/MISP/commit/4c1a03b20 5a6e4751-2f3f-4070-9419-94fb35b644e8
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-22 16:46 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-22 16:46 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-22 16:46 UTC -
web:support.sap.com
SAP security patch day bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 14 th of April 2026 , SAP security patch day saw the release of 19 new security notes. There is 1 update to previously ...
2026-09-22 16:46 UTC -
web:support.sap.com
SAP security Patch Day Bulletin This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape. On 9th of June 2026 , SAP security patch day saw the release of 15 new security notes.
2026-09-22 16:46 UTC -
web:www.dell.com
Dell iDRAC9 remediation for an Improper Access Control security vulnerability that could be exploited by malicious users to compromise the affected system.
2026-09-22 16:46 UTC -
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
2026-09-22 16:46 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-22 16:46 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-22 16:46 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's September 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-09-22 16:46 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-94374.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94374",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:21:38.785106Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:21:57.870Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"app/Model/Event.php (processModuleResultsData / handleModuleResults)"
],
"product": "MISP",
"programFiles": [
"app/Model/Event.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute and object processing loops, the report loop did not unset the client-supplied 'id' field before calling save(). Because the MISP EventReport model's create() method does not strip the id field, an authenticated user with permission to submit module results could include an 'id' value referencing an existing report belonging to a different event. Upon save(), the ORM would update that existing row rather than insert a new one, allowing the attacker to </p>\u2003- read the content of another event's report by reparenting it into their own event<br>\u2003- overwrite the report's fields with attacker-controlled data<br><div>\u2003- change the report's event_id to redirect ownership. </div><div><br></div><p>This constitutes an authorization bypass through a user-controlled key, enabling cross-event data disclosure and integrity compromise. The vulnerability requires an authenticated session with the ability to invoke module result processing on an event.</p><p>Version affected: <2.5.47</p>"
}
],
"value": "MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute and object processing loops, the report loop did not unset the client-supplied 'id' field before calling save(). Because the MISP EventReport model's create() method does not strip the id field, an authenticated user with permission to submit module results could include an 'id' value referencing an existing report belonging to a different event. Upon save(), the ORM would update that existing row rather than insert a new one, allowing the attacker to\u00a0\n\n\u2003-\u00a0read the content of another event's report by reparenting it into their own event\n\u2003-\u00a0overwrite the report's fields with attacker-controlled data\n\u2003-\u00a0change the report's event_id to redirect ownership.\u00a0\n\n\n\n\nThis constitutes an authorization bypass through a user-controlled key, enabling cross-event data disclosure and integrity compromise. The vulnerability requires an authenticated session with the ability to invoke module result processing on an event.\n\nVersion affected: <2.5.47"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-472",
"description": "CWE-472 External Control of Assumed-Immutable Web Parameter",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T12:25:02.628Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/4c1a03b20"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The fix adds an unset($report['id']) call in the EventReport processing loop within processModuleResultsData, immediately before the event_id assignment and save() call. This ensures that any client-supplied id field is stripped from the report data, forcing the ORM to perform an insert (new report) rather than an update (existing report), consistent with the existing behavior of the attribute and object loops in the same method.</p>"
}
],
"value": "The fix adds an unset($report['id']) call in the EventReport processing loop within processModuleResultsData, immediately before the event_id assignment and save() call. This ensures that any client-supplied id field is stripped from the report data, forcing the ORM to perform an insert (new report) rather than an update (existing report), consistent with the existing behavior of the attribute and object loops in the same method."
}
],
"title": "MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "review",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact affected and fixed MISP version numbers are not stated in the patch metadata; the tag boundary (v2.5.47, 53 commits after fix) suggests the fix landed after v2.5.47 but the precise fixed release is unspecified.",
"PR:L assumes that submitting module results is available to any authenticated user with write access to an event; if MISP requires a more restrictive role (e.g., admin or org admin), PR should be raised to H.",
"VC:L assumes the attacker can read only the specific report they target by id; if the reparenting exposes additional data (e.g., related attributes), the confidentiality impact could be higher.",
"CAPEC-126 (Parameter Tampering) is the closest available CAPEC; the actual technique is more precisely a mass-assignment / IDOR via unsanitized primary key, for which no dedicated CAPEC entry exists.",
"The Co-Authored-By line references an AI assistant (Claude Opus 4.8); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker tampers with the module-results payload by injecting an 'id' parameter that the application does not expect or sanitize, redirecting the save operation to an arbitrary existing report row. This is the closest CAPEC to the observed attack: manipulating a request parameter to alter application behavior and access an unauthorized object. The mapping is approximate because CAPEC-126 typically describes in-transit tampering, whereas here the parameter is included in the initial request body; however, no more specific CAPEC for mass-assignment IDOR exists in the CAPEC catalog."
}
],
"commit": "4c1a03b200fc75854879897c9cfc33a86b965d11",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
}
],
"cvssRationale": "AV:N \u2013 MISP is a network-accessible web application. AC:L \u2013 the attack requires only including an 'id' field in a normal module-results submission; no race condition or complex bypass is needed. AT:N \u2013 no prior user interaction or attack preparation beyond crafting the payload. PR:L \u2013 requires an authenticated user with permission to submit module results on an event (a common MISP role). UI:N \u2013 no victim interaction required. VC:L \u2013 the attacker can read the content of one specific report they target by id. VI:H \u2013 the attacker can overwrite all fields of the targeted report and change its event_id, fully compromising its integrity. VA:N \u2013 no availability impact. SC/SI/SA \u2013 no impact on adjacent systems; SI:H reflects the integrity compromise of the shared report data store.",
"fixSummary": "The fix adds an unset($report['id']) call in the EventReport processing loop within processModuleResultsData, immediately before the event_id assignment and save() call. This ensures that any client-supplied id field is stripped from the report data, forcing the ORM to perform an insert (new report) rather than an update (existing report), consistent with the existing behavior of the attribute and object loops in the same method.",
"generatedAt": "2026-09-21T12:19:38.677403Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "1079aff9d4e4710ba6c4ea950bcbbe2597411bfe7065efbc1bc9a5587f87a6c9",
"patchSummary": "In app/Model/Event.php, within the foreach loop over $resolved_data['EventReport'] in processModuleResultsData, a single line unset($report['id']); is inserted after $this->EventReport->create() and before $report['event_id'] = $id. A four-line comment is added explaining that module-result import only creates reports and that stripping the client id prevents redirecting save() onto another event's report row. No other files or logic are modified.",
"patchTruncated": false,
"patches": [
{
"commit": "4c1a03b200fc75854879897c9cfc33a86b965d11",
"patchSha256": "1079aff9d4e4710ba6c4ea950bcbbe2597411bfe7065efbc1bc9a5587f87a6c9",
"source": "https://github.com/MISP/MISP/commit/4c1a03b20.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/4c1a03b20.patch",
"subject": "fix: [security] Strip the client id from module-result event"
}
],
"source": "https://github.com/MISP/MISP/commit/4c1a03b20.patch",
"subject": "fix: [security] Strip the client id from module-result event",
"tagVersionBoundary": {
"commits_after_fix": 53,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-639",
"rationale": "The attacker supplies an 'id' value in the module-results payload that the application uses as the primary key for the save() operation, redirecting the write to an object (report row) belonging to a different event. The user-controlled key bypasses the intended create-only semantics and grants unauthorized read/write access to another event's report."
},
{
"cweId": "CWE-472",
"rationale": "The 'id' field is assumed to be server-generated and immutable for new records, but the application accepts a client-supplied value and passes it directly to the ORM save() call, allowing the attacker to control which database row is affected."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20022"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-94374",
"datePublished": "2026-09-21T12:25:02.628Z",
"dateReserved": "2026-09-21T12:25:00.527Z",
"dateUpdated": "2026-09-21T15:21:57.870Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}