以下是该漏洞描述信息的中文翻译: 受影响版本的 MISP 中,仪表板上显示组织信息的组件之间存在不一致的授权检查。 几个与组织相关的组件未遵守 配置项。因此,即使正常的组织索引已被有意隐藏,拥有认证但缺少 权限的用户仍能够枚举(列出)各个组织。 受影响的组件包含以下路径: 返回组织名称和标识符; 由于无限制的 查询获取了完整的数据行,JSON 导出可能会暴露更多的组织数据库字段; 接受 或负数值,这在效果上等同于移除结果数量限制,从而返回整个组织表。 一个相关的“组织贡献者排行榜”组件也忽略了同样的可见性设置。其处
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86452 | 8.7 HIGH | MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Floodi |
| CVE-2026-86347 | 7.1 HIGH | MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion |
| CVE-2026-86408 | 7.1 HIGH | MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected E |
| CVE-2026-86419 | 7.0 HIGH | MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed R |
| CVE-2026-86342 | 5.3 MEDIUM | MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Inform |
| CVE-2026-86417 | 5.3 MEDIUM | MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Us |
| CVE-2026-86451 | 5.3 MEDIUM | MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects |
| CVE-2026-86351 | 5.1 MEDIUM | MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL |
| CVE-2026-86440 | 5.1 MEDIUM | MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs |
| CVE-2026-86418 | 2.3 LOW | MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Us |
No comments yet