PatchSiren cyber security CVE debrief
CVE-2026-10854 misp CVE debrief
A visibility control issue was discovered in the event template creation workflow of MISP, allowing non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access restrictions, potentially exposing private galaxy metadata such as galaxy type and description to users who should not have visibility.
- Vendor
- misp
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-04
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-06-04
- Advisory updated
- 2026-07-22
Who should care
Site administrators and users of MISP, particularly those with non-site-admin roles, should be aware of this issue and take necessary actions to restrict access to private galaxies.
Technical summary
The issue was caused by the event template builder loading all enabled galaxies without applying organisation or distribution-based access restrictions. This allowed non-site-admin users to access private galaxies belonging to other organisations.
Defensive priority
MEDIUM
Recommended defensive actions
- Restrict galaxy queries for non-site-admin users to galaxies owned by the user's organisation or galaxies with a non-private distribution setting.
- Site administrators should review and update access controls to ensure that private galaxies are only accessible to authorised users.
Evidence notes
The issue has been fixed by restricting galaxy queries for non-site-admin users to galaxies owned by the user's organisation or galaxies with a non-private distribution setting. Site administrators retain visibility of all enabled galaxies.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/MISP/MISP/commit/d3adfe1a097dd4b403364e9af34e208660eeec1a
5a6e4751-2f3f-4070-9419-94fb35b644e8 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.