CVE-2026-103858EPSS p11.2%
CVE-2026-103858CVE-2026-103858
Description
MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.
As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:
- Read the thread title and the content of the quoted post
- Submit a new post into the discussion thread
This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).
Affected: <2.5.48
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |