{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-103858","assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","state":"PUBLISHED","assignerShortName":"CIRCL","dateReserved":"2026-10-01T11:31:31.101Z","datePublished":"2026-10-01T11:31:32.840Z","dateUpdated":"2026-10-01T15:00:57.587Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["PostsController (discussion/thread posting)"],"product":"MISP","programFiles":["app/Controller/PostsController.php"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"unspecified","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Bastien Bossiroy and Célien Desteucq of NCIA"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.</p><p>As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:</p><p>- Read the thread title and the content of the quoted post</p><p>- Submit a new post into the discussion thread</p><p>This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).</p><p>Affected: &lt;2.5.48</p>"}],"value":"MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.\n\nAs a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:\n\n- Read the thread title and the content of the quoted post\n\n- Submit a new post into the discussion thread\n\nThis constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).\n\nAffected: <2.5.48"}],"impacts":[{"capecId":"CAPEC-10","descriptions":[{"lang":"en","value":"CAPEC-10 Parameter Tampering"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-01T11:16:47Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-285","description":"CWE-285 Improper Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL","dateUpdated":"2026-10-01T11:31:32.840Z"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/79fbd4c75"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.</p>"}],"value":"The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association."}],"title":"MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The exact affected version range is uncertain; the tag boundary v2.5.48 with 42 commits after the fix suggests the fix landed around or before v2.5.48, but the precise first-affected and first-fixed versions are not stated in the patch.","The checkIfAuthorised() method is assumed to enforce the full thread ACL including sharing groups and event visibility, based on the commit message description; the method's implementation is not included in the patch.","CAPEC-10 (Parameter Tampering) is the closest available CAPEC mapping; no CAPEC specifically covers 'incomplete authorization check on a direct object reference' was identified in the catalog.","The CVSS assumes the attacker already possesses a valid MISP account (PR:L); unauthenticated access is not indicated by the patch.","The AI co-author (Claude Opus 5.5) is credited as a tool rather than a person, per the Co-Authored-By line."],"capecRationale":[{"capecId":"CAPEC-10","rationale":"The attacker manipulates the target_id parameter (thread_id or post_id) in the posts/add request to reference a thread or post they do not have full access to. The incomplete server-side authorization check then permits the operation. CAPEC-10 is the closest available pattern for exploiting a server's failure to properly validate the authorization context of a user-supplied resource identifier. Uncertainty: no CAPEC specifically named 'Insecure Direct Object Reference' or 'Broken Access Control via Incomplete ACL' exists in the CAPEC catalog, so Parameter Tampering is the best available match."}],"commit":"79fbd4c7580adc0518581351c3d8c3d5b3ac7c97","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Bastien Bossiroy and Célien Desteucq of NCIA"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"}],"cvssRationale":"AV:N: web application accessible over network. AC:L: attacker only needs a valid thread_id or post_id, no race conditions or special timing. AT:N: no special attack prerequisites beyond authentication. PR:L: requires an authenticated MISP user account. UI:N: no victim interaction needed; the attacker directly issues the request. VC:L: attacker can read thread titles and quoted post content they should not see. VI:L: attacker can inject posts into unauthorized threads. VA:N: no availability impact. SC/SI/SA:N: no impact on subsequent components. The impact is bounded to the MISP instance's data and does not compromise the server or other systems.","fixSummary":"The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.","generatedAt":"2026-10-01T11:16:47.016611Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":5,"confidence":"medium","model":"qwen3.8:27b","score":7}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938","patchSummary":"In PostsController.php add() method: (1) For the 'thread' target case, replaced the inline distribution==0 and org_id comparison with a call to Thread->checkIfAuthorised() before reading the thread; removed the separate _isSiteAdmin() bypass. (2) For the 'post' target case, added a check that the post has a non-empty thread_id, replaced the same limited distribution/org check with Thread->checkIfAuthorised(), and reordered the thread read to occur after the authorization check. Net: 8 insertions, 12 deletions in one file.","patchTruncated":false,"patches":[{"commit":"79fbd4c7580adc0518581351c3d8c3d5b3ac7c97","date":"Wed, 23 Sep 2026 15:27:08 +0200","patchSha256":"04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938","source":"https://github.com/MISP/MISP/commit/79fbd4c75.patch","sourceUrl":"https://github.com/MISP/MISP/commit/79fbd4c75.patch","subject":"fix: [security] Apply the thread ACL when posting to a"}],"source":"https://github.com/MISP/MISP/commit/79fbd4c75.patch","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-01T11:16:47Z","version":"2.0.3"},"subject":"fix: [security] Apply the thread ACL when posting to a","tagVersionBoundary":{"commits_after_fix":42,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-285","rationale":"The authorization check was present but incomplete: it only verified org-level distribution (distribution==0) and org_id match, failing to enforce sharing-group membership and event-level ACL. This is a classic case of insufficient authorization logic rather than a completely missing check, making CWE-285 more precise than CWE-862."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (79fbd4c7580adc0518581351c3d8c3d5b3ac7c97): fix: [security] Apply the thread ACL when posting to a","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/79fbd4c75.patch"],"timestamp":"2026-09-23T13:27:08Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20244"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-01T15:00:37.761849Z","id":"CVE-2026-103858","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-01T15:00:57.587Z"}}]}}