SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86283

HIGH · CVSS 7.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the MISP platform's UiBeta theme, specifically in the CollectionsController::view() action, which fails to enforce proper access controls when querying event details by UUID. This oversight allows authenticated users with view access to collections to access sensitive event information they are not authorized to see, leading to potential horizontal privilege escalation. Organizations using MISP should prioritize addressing this vulnerability to protect sensitive data and maintain proper access controls within their instances.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86283
Severity
HIGH
CVSS
7.1
EPSS
0.23%

Original NVD Description

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces per-user event ACL. However, the view template independently re-queried the same UUIDs using only an Event.uuid IN (...) condition, omitting the createEventConditions() authorization filter. Because collection element UUIDs are stored without server-side authorization against the referenced event (CollectionElementsController::add() accepts whatever UUID the collection owner posts), an authenticated user with view access to a collection could retrieve full details of events they are not permitted to read. The exposed data included event identifiers, info, dates, timestamps, creator organization, all event tags, and galaxy clusters (the latter attached via a cluster-scoped rather than event-scoped ACL check). This constitutes an authorization bypass at the presentation layer, allowing horizontal privilege escalation across event boundaries within the MISP instance.