Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-86408

Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type * key_data * fingerprint but did not fetch or authorize the associated parent event first. The upstream commit explicitly states that cryptographicKeys/view could return a protected event’s signing key to any authenticated user. The fix adds parent_id and parent_type to the lookup and then enforces authorization through the associated event using fetchSimpleEvent($user, parent_id). If the parent is not an Event, access is limited to site administrators. Version affected: ≤2.5.45
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.9%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-86408


Contact Us

Shodan ® - All rights reserved