CVE-2026-90955

MISP: Omission of Security-relevant Information (CVE-2026-90955)

mediumEPSS 0.2%

Affected

  • Open Source/MISP < *..2.5.46

Fixed in

  • Open Source/MISP 2.5.46

Description

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user. Version affected: ≤2.5.45

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

Open SourceMISP
< 2.5.46fixed in 2.5.46

Metrics

4.6
Source: cna-v4
4.6 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-14 12:37 UTC
CWE-223, CWE-778

Weakness classes (CWE)

  • CWE-223Base

    Omission of Security-relevant Information

    The product does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.

    cwe.mitre.org →
  • CWE-778Base

    Insufficient Logging

    When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-09-14 13:19 UTC· 5a6e4751-2f3f-4070-9419-94fb35b644e8
    • Description: Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user. Version affected: ≤2.5.45
    • CVSS V4.0: AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-223
    • CWE: CWE-778
  2. CVE Modified2026-09-14 13:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-90955","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…