Vulnerability Description
Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted distribution but supplied a different sharing_group_id, that authorization branch was skipped. Later, MISP’s field-recovery logic restored the existing event distribution from storage. For events already configured with sharing-group distribution, the unauthorized sharing-group ID could therefore be saved. The fix adds authorization checks in both the controller and Event::_edit() whenever a non-empty sharing_group_id is supplied without distribution. The model now calls SharingGroup::checkIfAuthorised() before persisting the change. Version affected: ≤2.5.45
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-91825?
CVE-2026-91825 is a documented vulnerability. Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the r...
How severe is CVE-2026-91825?
CVSS scoring is not yet available for CVE-2026-91825. Check NVD for updates.
Is there a patch for CVE-2026-91825?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.