CVE-2026-54360 | MISP up to 2.5.39 SharingGroupsController.php create ID authorization (EUVD-2026-36552)

SecurityVulns

A vulnerability categorized as critical has been discovered in MISP up to 2.5.39. Impacted is the function create of the file app/Controller/SharingGroupsController.php. Executing a manipulation of the argument ID can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-54360. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More