{"id":"CVE-2026-94381","published":"2026-09-21T13:17:13.360","lastModified":"2026-09-21T15:17:39.077","description":"MISP has a security issue that can let a user gain more access than their API key is supposed to allow.\n\nA read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function could accidentally restore the user’s normal account permissions. This means someone with a read-only API key could potentially gain write, delete, or even administrator access if their underlying account has those permissions.\n\nExploiting the issue requires a valid read-only API key and a single request to the affected function.\n\nThe main impact is that MISP’s API key restrictions can be bypassed, allowing actions that the API key was specifically meant to prevent.\n\n\n\n\nVersion affected: <2.5.47","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://github.com/MISP/MISP/commit/fd27e592a","tags":[]}],"exploitRefs":[{"url":"https://github.com/MISP/MISP/commit/fd27e592a","tags":[]}],"hasPoc":true,"ai":null}