NONE · 0

CVE-2026-60124

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. W...

Vulnerability Description

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write path did not verify event modification rights before saving the module output. This could allow a view-only user to inject or alter event data, impacting the integrity of MISP event content. The issue was fixed by enforcing the same modification-rights check used by related module result handling paths before processing misp_standard imports.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-60124?

CVE-2026-60124 is a documented vulnerability. An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. W...

How severe is CVE-2026-60124?

CVSS scoring is not yet available for CVE-2026-60124. Check NVD for updates.

Is there a patch for CVE-2026-60124?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.