CVE-2026-61474
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
09/07/2026
Description
An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the corresponding sharing group authorization check, as long as the attribute distribution value was not explicitly set to 4 — “sharing group”.<br />
<br />
<br />
As a result, a user could reference or associate an attribute with a sharing group they were not authorized to use. This could lead to an access-control bypass affecting the integrity of attribute sharing metadata and potentially expose or misuse restricted sharing group relationships.<br />
<br />
<br />
The patch changes the authorization logic so that the sharing group permission check is performed whenever a non-empty sharing_group_id is provided, regardless of the selected distribution value.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM


