tag
Misp
CVE-2026-56423
web
HIGH 8.8
MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
MISP's bulk-deletion endpoints for Event Reports (/eventReports/deleteSelection) and Sharing Groups (/sharingGroups/deleteSelection) authorize each selected item using a checkModifyCallback that discards the item id and instead returns the acting user's…
Patched
2026-07-27