SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85546

HIGH · CVSS 8.6 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the MISP platform's sharing group quick-edit functionality, allowing attackers to exploit a cross-site request forgery (CSRF) flaw due to improper HTTP method validation. This could enable unauthorized modifications to sharing group memberships, potentially granting unintended access to sensitive information or disrupting legitimate data sharing. Organizations using MISP should prioritize addressing this vulnerability to safeguard against unauthorized access and maintain the integrity of their information-sharing processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85546
Severity
HIGH
CVSS
8.6
EPSS
0.20%

Original NVD Description

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these operations to POST requests was commented out. As a result, these state-changing actions could be invoked using GET requests. An attacker could craft a URL targeting one of the affected actions and cause an authenticated MISP user with sufficient privileges to request it, for example through a malicious link or embedded web resource. Successful exploitation could modify the membership of a MISP sharing group without the victim intentionally performing the operation. Depending on the action performed, an attacker could add or remove organisations or servers from a sharing group, potentially granting unintended access to information distributed through that sharing group or disrupting legitimate information sharing. The patch restores HTTP method enforcement centrally in __initialiseSGQuickEdit() by calling allowMethod(['post']), ensuring that all four affected quick-edit operations require POST requests and are therefore subject to the application's normal protections for state-changing requests.