PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86342 MISP CVE debrief

CVE-2026-86342 debrief based on CVE Program and NVD records. Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality, potentially exposing restricted event correlations and associated event information. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. MISP users and administrators should assess exposure and prioritize patching. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison.

Vendor
MISP
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

MISP users and administrators should assess exposure and prioritize patching due to potential exposure of restricted event correlations and associated event information. This requires attention from MISP users and administrators to verify MISP version and patch status, and to review compensating controls for exposed systems.

Why it matters

CVE-2026-86342 requires attention from MISP users and administrators due to improper authorization checks in freetext feed preview functionality, potentially exposing restricted event correlations and associated event information. Prioritization of patching and verification of MISP version is necessary.

  • Potential exposure of restricted event correlations and associated event information
  • Possible unauthorized access to sensitive event data
  • Need for verification of MISP version and patch status
  • Potential impact on incident response and threat intelligence activities

Technical summary

MISP versions ≤2.5.45 contain improper authorization checks in freetext feed preview functionality, allowing restricted event correlations and associated event information exposure. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently.

Defensive priority

Medium priority for MISP users and administrators

Recommended defensive actions

  • Review and apply patches for MISP versions ≤2.5.45
  • Restrict access to MISP freetext feed preview functionality
  • Monitor MISP event correlations and associated event information exposure
  • Verify MISP version and patch status
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

CVE Program and NVD records detail improper authorization checks in MISP freetext feed preview functionality, allowing restricted event correlations and associated event information exposure. Fixes apply caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86342 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86342

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86342 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86342

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/MISP/commit/1fb622046

    5a6e4751-2f3f-4070-9419-94fb35b644e8

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/MISP/commit/4b6916086

    5a6e4751-2f3f-4070-9419-94fb35b644e8

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/MISP/commit/dc1a0f7c2

    5a6e4751-2f3f-4070-9419-94fb35b644e8

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MISP/MISP/commit/dedb4b297

    5a6e4751-2f3f-4070-9419-94fb35b644e8

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.