CVE-2026-9136Disclosure(misp-project / misp)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch misp-project misp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an instruction to update an existing record, an authenticated user able to submit shadow attribute proposals could provide the identifier of an existing ShadowAttribute and cause that record to be updated instead of creating a new proposal. This can result in unauthorized modification of existing shadow attributes, potentially affecting proposals associated with events the user should not be able to alter. Depending on deployment configuration and accessible API responses, the issue may also expose or move proposal data across event contexts. The vulnerability is caused by trusting a client-supplied primary key during object creation. The fix removes the id field from incoming ShadowAttribute data before processing, ensuring that the endpoint always creates a new proposal rather than updating an existing one. This has been fixed in MISP 2.5.38.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • misp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
misp

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-21: 1Mentions · 2026-05-24: 1Mentions · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-24: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-24: 105-2105-2405-29
Signal classification3 categories
Disclosure
133.3%
PoC
133.3%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-241
PoC1
2026-05-291
General1
Full discourse3 posts
  • Seth Kraft@skraft09
    Disclosure

    Proud to announce two new vulnerabilities were published today from my independent research! 🎉 Affecting MISP version 2.5.37 and prior. CVE-2026-9136 👉 https://github.com/advisories/GHSA-hfjr-4239-84fm CVE-2026-9137 👉 https://github.com/advisories/GHSA-gfvj-j222-m85v - Wrote two security patches to resolve the vulnerabilities. - Maintainer reviewed, approved, and merged the fixes. - Fixes are included in the release of MISP 2.5.38. Grateful for the opportunity to collaborate with the MISP Team! #TogetherWeHitHarder

    Post summary

    The author announces two newly published CVEs affecting MISP 2.5.37 and earlier, with patches already merged into the 2.5.38 release.

    01063389
    570 followersView on X
  • Seth Kraft@skraft09
    PoC

    I found an IDOR in MISP 2.5.37 (CVE-2026-9136) 🎉 Published a write-up for educational purposes 👉https://github.com/skraft9/vulnerability-research/blob/main/write-ups/CVE-2026-9136.md A massive shout-out to MISP Team for their exceptional responsiveness and support throughout this disclosure. #TogetherWeHitHarder https://t.co/cX4X2VnVRI

    Post summary

    Disclosed an IDOR in MISP 2.5.37 and shared a write‑up with a PoC for educational purposes.

    01020212
    364 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos MISP ❗ CVE-2026-9136 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-misp/ https://t.co/1Mlbz4yHgd

    Post summary

    A new CVE (CVE-2026-9136) affecting MISP products is announced, with a link provided for more information but no further technical or exploit details.

    00010129
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmisp-projectmisp---

Explore more