MISP Unauthorized Access to Import Module Functionality Vulnerability

Vulnerability

A vulnerability in MISP allows an authenticated user to access restricted import module functionality, potentially leading to unauthorized import or modification of event data. This issue arises because the importModule() function did not properly enforce per-organization module restrictions. As a result, users from organizations not allowed to use certain modules could still invoke them directly if they knew the module names. The vulnerability affects MISP versions prior to the patch included in commit 0ed79b4.

Impact

Exploitation of this vulnerability could result in unauthorized access to import modules, allowing users to import or modify event data through modules that should be restricted based on their organization's permissions.

Remediation

Users can update to the latest version of MISP, where this vulnerability has been addressed, to mitigate this issue.

Added: Jul 8, 2026, 2:23 PM
Updated: Jul 8, 2026, 2:23 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.9
remediation
7.7
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.