CVE-2026-56422Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistently stripping, pinning, or revalidating them against the server-authorized object. In affected paths, an authenticated user with access to one authorized object could submit crafted REST or form payloads that caused MISP to save data against a different object than the one checked by the authorization logic. Depending on the endpoint, this could allow object overwrite, object re-parenting, ownership transfer, unauthorized sharing-group scoping, event/object injection, proposal retargeting, or stored attacker-controlled content appearing in another user’s context. The fixes harden affected create/edit/import flows by stripping client-supplied primary keys on create-only saves, re-pinning route- or database-authorized identifiers before save operations, validating effective sharing-group scope, and adding field whitelists where ownership fields must never be editable. The initial broad fix also added a central CRUDComponent::edit() primary-key re-pin so payload-supplied IDs cannot redirect saves away from the already-authorized row. GitHub’s patch for 7acf8220c describes this central issue as CRUDComponent::edit() copying supplied fields, including a payload primary key, onto the loaded record, allowing CakePHP save() to update an arbitrary row unless the loaded ID is re-pinned.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-06-22); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-06-22: 4Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-07-06: 1Active Exploitation · 2026-06-23: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 4Technical Details · 2026-06-24: 106-2206-2306-2407-06
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-224
Disclosure4
2026-06-231
Active Exploitation1
2026-06-241
Disclosure1
2026-07-061
General1
Full discourse7 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos MISP ❗ CVE-2026-56447 ❗ CVE-2026-56423 ❗ CVE-2026-56422 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-misp/ https://t.co/VkJ11jLE4b

    Post summary

    The post announces three MISP CVEs and links to a CERT page for more information, but provides no technical or exploit details.

    00030287
    6.7K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-56422 — MISP Authorisation bypass that could allow authenticated users to manipulate client-supplied identifiers. Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-22/TIER_2_CVE-2026-56422.md #CyberSecurity #ThreatIntelligence #VulnerabilityManagement #CyberObs

    Post summary

    The report announces a new CVE‑2026‑56422 vulnerability—a user‑auth Bypass enabling manipulation of identifiers—without providing exploit code or patch details.

    0000158
    55 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting MISP (CVE-2026-56422) https://vuldb.com/vuln/372669/cti

    Post summary

    The post indicates attackers are actively targeting the MISP CVE-2026-56422 vulnerability, but no PoC, exploit code, patch, or technical details are shared.

    00000100
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - MISP Multiple Security Vulnerabilities (CVE-2026-56422 & CVE-2026-56425) CVE-2026-56422- Multiple MISP core controllers and models accept client-controlled primary keys (id) and foreign keys (event_id, org_id, user_id, sharing_group_id, etc.) without proper revalidation. An authenticated user can overwrite objects, re-parent data, transfer ownership, or inject content into other users' contexts. This is a broad Mass Assignment / Authorization Bypass issue (CWE-639) affecting many create/edit/import flows. CVE-2026-56425- MISP's AAD Authentication Plugin contains multiple weaknesses in its OAuth 2.0 flow: session IDs exposed as OAuth state parameters, no session regeneration post-login, missing single-use nonce enforcement, no HTTPS enforcement on redirect URIs, and verbatim logging of attacker-controlled error parameters. Combined, these enable session hijacking, session fixation, CSRF, replay attacks, and log injection. 👉Affected: MISP (pre-fix versions). Fixed in: Latest MISP. Upgrade to latest.

    Post summary

    MISP faces two high‑severity CVEs—one involving mass assignment via unvalidated primary keys and another exposing OAuth 2.0 weaknesses—both fixable by upgrading to the latest version.

    00000102
    226 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56422 Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id,… https://www.cve.org/CVERecord?id=CVE-2026-56422 ----- Traducción: CVE-2026-56422 Múl… http://infoflow.cloud`

    Post summary

    The post announces the existence of CVE-2026‑56422 with some technical detail but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000042
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56422 Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id,… https://www.cve.org/CVERecord?id=CVE-2026-56422

    Post summary

    The text announces CVE‑2026‑56422, describing how MISP controllers can accept untrusted request fields, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000722
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56422 Improper Input Validation in MISP Core Controllers Enables Unauthorized Object Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56422

    Post summary

    The post announces CVE-2026-56422, highlighting that improper input validation in MISP Core Controllers can lead to unauthorized object manipulation, but it does not provide exploit code, patch details, or evidence of active exploitation.

    00000150
    4.1K followersView on X

Explore more