以下是该漏洞描述的中文翻译: MISP 受影响的版本中,仪表板(Dashboard)中的组织选择器(organisation picker)在展示组织元数据时,未应用与常规组织索引及单组织视图所强制执行的相同可见性限制。 受影响的端点返回了以下字段: 组织 ID; UUID; 名称。 当启用 配置时,常规的组织枚举被限制,但仪表板选择器仍会查询所有组织。这使得已认证用户能够发现本应对其隐藏的组织。 修复方案调用 ,并将由此生成的访问控制列表(ACL)条件追加到选择器的查询中。这样一来,普通用户仅能查看与其已可见事件
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86452 | 8.7 HIGH | MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Floodi |
| CVE-2026-86347 | 7.1 HIGH | MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion |
| CVE-2026-86408 | 7.1 HIGH | MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected E |
| CVE-2026-86419 | 7.0 HIGH | MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed R |
| CVE-2026-86342 | 5.3 MEDIUM | MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Inform |
| CVE-2026-86417 | 5.3 MEDIUM | MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Us |
| CVE-2026-86451 | 5.3 MEDIUM | MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects |
| CVE-2026-86351 | 5.1 MEDIUM | MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL |
| CVE-2026-86440 | 5.1 MEDIUM | MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs |
| CVE-2026-86441 | 2.3 LOW | MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidd |
No comments yet