CVE-2026-54398
Last modified
CVE-2026-54398 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group validation was performed against the wrong request data structure after object fields had been merged to the top level, causing the check to be bypassed. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group validation was performed against the wrong request data structure after object fields had been merged to the top level, causing the check to be bypassed. In addition, attributes embedded in objects were not individually validated for authorized sharing group use. An attacker could craft a request with distribution set to 4 and an arbitrary sharing_group_id, potentially disclosing the existence or name of otherwise non-visible sharing groups and improperly modifying the distribution metadata of objects or contained attributes.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54398?
How severe is CVE-2026-54398?
How do I fix CVE-2026-54398?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54390JTL Shop versions 5.2.0 through 5.7.1 contains a server-side…9.8
- CVE-2026-54393A stored cross-site scripting vulnerability exists in MISP w…5.1
- CVE-2026-54394MISP contains a path traversal vulnerability in Organisation…5.3
- CVE-2026-54395MISP contains a reflected cross-site scripting vulnerability…5.3
- CVE-2026-54396An information disclosure vulnerability exists in the MISP A…5.3
- CVE-2026-54397A vulnerability in MISP’s non-REST event editing path allowe…6.1
- CVE-2026-54399Uncontrolled Resource Consumption vulnerability in the HTTP/…7.5
- CVE-2026-5440A memory exhaustion vulnerability exists in the HTTP server …7.5
- CVE-2026-54400A malicious actor with access to the network and high privil…9.1
- CVE-2026-54401A malicious actor with access to the network and low privile…8.8
- CVE-2026-54402A malicious actor with access to the network and low privile…8.8
- CVE-2026-54403A malicious actor with access to the network could exploit a…8.6
Are you affected by CVE-2026-54398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
