PatchSiren cyber security CVE debrief
CVE-2026-86342 MISP CVE debrief
CVE-2026-86342 debrief based on CVE Program and NVD records. Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality, potentially exposing restricted event correlations and associated event information. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. MISP users and administrators should assess exposure and prioritize patching. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison.
- Vendor
- MISP
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
MISP users and administrators should assess exposure and prioritize patching due to potential exposure of restricted event correlations and associated event information. This requires attention from MISP users and administrators to verify MISP version and patch status, and to review compensating controls for exposed systems.
Why it matters
CVE-2026-86342 requires attention from MISP users and administrators due to improper authorization checks in freetext feed preview functionality, potentially exposing restricted event correlations and associated event information. Prioritization of patching and verification of MISP version is necessary.
- Potential exposure of restricted event correlations and associated event information
- Possible unauthorized access to sensitive event data
- Need for verification of MISP version and patch status
- Potential impact on incident response and threat intelligence activities
Technical summary
MISP versions ≤2.5.45 contain improper authorization checks in freetext feed preview functionality, allowing restricted event correlations and associated event information exposure. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently.
Defensive priority
Medium priority for MISP users and administrators
Recommended defensive actions
- Review and apply patches for MISP versions ≤2.5.45
- Restrict access to MISP freetext feed preview functionality
- Monitor MISP event correlations and associated event information exposure
- Verify MISP version and patch status
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
CVE Program and NVD records detail improper authorization checks in MISP freetext feed preview functionality, allowing restricted event correlations and associated event information exposure. Fixes apply caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86342 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86342
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86342 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86342
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/MISP/MISP/commit/1fb622046
5a6e4751-2f3f-4070-9419-94fb35b644e8
-
Source reference
Unverified legacy reference
URL: https://github.com/MISP/MISP/commit/4b6916086
5a6e4751-2f3f-4070-9419-94fb35b644e8
-
Source reference
Unverified legacy reference
URL: https://github.com/MISP/MISP/commit/dc1a0f7c2
5a6e4751-2f3f-4070-9419-94fb35b644e8
-
Source reference
Unverified legacy reference
URL: https://github.com/MISP/MISP/commit/dedb4b297
5a6e4751-2f3f-4070-9419-94fb35b644e8
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.