CVE Explorer
CVE-2026-10855
An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existing template. As a result, an authenticated user with access to the template import functionality could forcibly overwrite an event template owned by another organization.
Successful exploitation cou
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"misp","repo":"https://github.com/misp/misp","vendor":"misp","versions":[{"lessThanOrEqual":"2.5.38","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ec361ee28e5e7d7a5f3826efaf05a7b3a3a630bd8ce323a10d7acd111cf66074 · sha256:5086443e832b1961… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ec361ee28e5e7d7a5f3826efaf05a7b3a3a630bd8ce323a10d7acd111cf66074 · sha256:5086443e832b1961… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ec361ee28e5e7d7a5f3826efaf05a7b3a3a630bd8ce323a10d7acd111cf66074 · sha256:5086443e832b1961… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["patch"],"url":"https://github.com/MISP/MISP/commit/7c2200d143bef86aaf58d701b6968a843097db69"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ec361ee28e5e7d7a5f3826efaf05a7b3a3a630bd8ce323a10d7acd111cf66074 · sha256:5086443e832b1961… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.