Security
Loading…

CVE-2026-86417

UNKNOWN
Description

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw redacted data in the normal HTML interface could request the REST/JSON representation and receive template owners’ email addresses without the intended privilege check. The fix moves the decision to a centralized User::canSeeEmails() authorization helper. Email addresses are now fetched only when the requester is a site administrator or the instance explicitly enables Security.disclose_user_emails. The same helper is also reused by other dashboard widgets to keep email-disclosure policy consistent. Version affected: ≤2.5.45

Timeline
Published:September 7th, 2026 1:20 PM
Last modified:September 7th, 2026 1:20 PM
CVSS Scoring

No CVSS v3 score available

Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute