CVE Explorer
CVE-2026-54396
An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitted request data. An authenticated user with permission to edit an AuthKey could submit arbitrary user IDs and observe the returned dropdown data, allowing enumeration of user email addresses. The issue is fixed by deriving the dropdown user from the
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"misp","repo":"https://github.com/misp/misp","vendor":"misp","versions":[{"lessThan":"2.5.40","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0dccf2d1fa3471812337d034d4694ac8029f10560d55fff10085e482a5becca8 · sha256:edb0b17afa857bd9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NON…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0dccf2d1fa3471812337d034d4694ac8029f10560d55fff10085e482a5becca8 · sha256:edb0b17afa857bd9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0dccf2d1fa3471812337d034d4694ac8029f10560d55fff10085e482a5becca8 · sha256:edb0b17afa857bd9… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["patch"],"url":"https://github.com/MISP/MISP/commit/42737f4e88df801486334690913dd344e447fac3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0dccf2d1fa3471812337d034d4694ac8029f10560d55fff10085e482a5becca8 · sha256:edb0b17afa857bd9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.