PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10854 misp CVE debrief

A visibility control issue was discovered in the event template creation workflow of MISP, allowing non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access restrictions, potentially exposing private galaxy metadata such as galaxy type and description to users who should not have visibility.

Vendor
misp
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-04
Original CVE updated
2026-07-22
Advisory published
2026-06-04
Advisory updated
2026-07-22

Who should care

Site administrators and users of MISP, particularly those with non-site-admin roles, should be aware of this issue and take necessary actions to restrict access to private galaxies.

Technical summary

The issue was caused by the event template builder loading all enabled galaxies without applying organisation or distribution-based access restrictions. This allowed non-site-admin users to access private galaxies belonging to other organisations.

Defensive priority

MEDIUM

Recommended defensive actions

  • Restrict galaxy queries for non-site-admin users to galaxies owned by the user's organisation or galaxies with a non-private distribution setting.
  • Site administrators should review and update access controls to ensure that private galaxies are only accessible to authorised users.

Evidence notes

The issue has been fixed by restricting galaxy queries for non-site-admin users to galaxies owned by the user's organisation or galaxies with a non-private distribution setting. Site administrators retain visibility of all enabled galaxies.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10854 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10854

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10854 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10854

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/MISP/MISP/commit/d3adfe1a097dd4b403364e9af34e208660eeec1a

    5a6e4751-2f3f-4070-9419-94fb35b644e8 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.