CVE-2026-95697 Overview
CVE-2026-95697 is a missing authorization vulnerability [CWE-862] in the Malware Information Sharing Platform (MISP). The flaw resides in the captureOrg method of the Organisation model. When the $force parameter is set to true, the method overwrites organization metadata without verifying the caller's privileges. A user holding only a sharing group (SG) editor role can invoke this code path and modify fields reserved for site administrators or accounts with sync permissions.
Critical Impact
An authenticated SG editor can alter organization metadata such as type, nationality, sector, and contacts, enabling blueprint-based sharing group manipulation across the MISP instance.
Affected Products
- MISP (Malware Information Sharing Platform) instances prior to commit f3ec974ee
- MISP deployments exposing the web interface to SG editor accounts
- MISP servers relying on sharing groups and blueprints for data distribution
Discovery Timeline
- 2026-09-22 - CVE-2026-95697 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-95697
Vulnerability Analysis
The vulnerability is an authorization bypass in MISP's Organisation::captureOrg method located in app/Model/Organisation.php. The method is invoked when MISP processes incoming events, feeds, or sharing group definitions that reference organizations. When the caller passes $force = true, the method rewrites the target organization record with attacker-supplied metadata.
The pre-patch logic did not check the invoking user's role before performing the overwrite. Sharing group editors, who legitimately manage SG membership, gained an unintended write path into organization records. Because sharing group blueprints derive behavior from organization attributes, tampered metadata can influence distribution decisions across the instance.
The impact is scoped to the integrity of organization records and downstream sharing group configurations. Confidentiality and availability are not directly affected.
Root Cause
The root cause is a missing authorization check [CWE-862] on a privileged code branch. The $force flag was treated as sufficient justification to overwrite protected fields, without evaluating perm_site_admin or perm_sync on the acting user's role.
Attack Vector
Exploitation requires an authenticated MISP account with at least SG editor privileges and network reachability to the MISP web interface. The attacker submits or synchronizes data structures that cause captureOrg to execute with $force = true, then supplies crafted values for the protected metadata fields.
// Security patch in app/Model/Organisation.php
// Source: https://github.com/MISP/MISP/commit/f3ec974ee
$existingOrg[$this->alias]['uuid'] = $org['uuid'];
$changed = true;
}
- if ($force) {
+ if ($force && (!empty($user['Role']['perm_site_admin']) || !empty($user['Role']['perm_sync']))) {
$fields = array('type', 'date_created', 'date_modified', 'nationality', 'sector', 'contacts');
foreach ($fields as $field) {
if (isset($org[$field])) {
The patch gates the overwrite branch behind an explicit check for perm_site_admin or perm_sync on the calling user's role.
Detection Methods for CVE-2026-95697
Indicators of Compromise
- Unexpected modifications to type, nationality, sector, or contacts fields on organization records
- Changes to date_created or date_modified on Organisation entries that do not correlate with administrator activity
- Sharing group blueprint behavior that diverges from documented organization membership
- Audit log entries showing organization edits initiated by users without perm_site_admin or perm_sync
Detection Strategies
- Query the MISP audit log for Organisation model edits and correlate the acting user_id against role assignments
- Baseline organization metadata and alert on drift for fields modified by non-administrator accounts
- Review sharing group and blueprint change history for organization attribute changes preceding distribution anomalies
Monitoring Recommendations
- Forward MISP audit logs to a central SIEM and create rules for organization metadata writes by SG editor accounts
- Track use of the /organisations/edit and sync endpoints alongside role membership changes
- Alert on new or repeated failures and successes involving organization record updates from non-admin sessions
How to Mitigate CVE-2026-95697
Immediate Actions Required
- Update MISP to a build that includes commit f3ec974ee from the MISP GitHub repository
- Audit accounts with the SG editor role and remove the privilege where it is not operationally required
- Review recent organization record changes and restore trusted values where tampering is suspected
Patch Information
The fix is committed to the MISP project as f3ec974ee in app/Model/Organisation.php. The patch adds an authorization check that permits the $force overwrite branch only when the invoking user has perm_site_admin or perm_sync. Administrators should upgrade to a MISP release containing this commit and restart the application.
Workarounds
- Restrict SG editor role assignments to a minimal set of trusted users until patching is complete
- Limit network access to the MISP web interface and API to known analyst networks
- Increase audit log retention and review frequency for organization and sharing group changes
# Verify the patched commit is present in your MISP checkout
cd /var/www/MISP
sudo -u www-data git log --oneline app/Model/Organisation.php | grep f3ec974ee
sudo -u www-data git pull origin 2.4
sudo systemctl restart apache2
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
