{"id":"CVE-2019-16202","title":"MISP before 2.4.115 allows privilege escalation in certain situations","summary":"MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a \"This could be an indication of an attempted privilege escalati…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-269"],"vendor":"misp-project","product":"misp","affected":["misp < 2.4.115"],"patched":["misp 2.4.115"],"published":"2019-09-10","updated":"2026-06-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-16202","references":[{"url":"https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/","label":"cve@mitre.org"},{"url":"https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f","label":"cve@mitre.org"},{"url":"https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115","label":"cve@mitre.org"},{"url":"https://excellium-services.com/cert-xlm-advisory/cve-2019-16202/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/MISP/MISP/commit/75acd63c46506ad404764c3a3de7d4ca11d0560f","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/MISP/MISP/compare/v2.4.114...v2.4.115","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01335,"epssPercentile":0.69477,"ingestedAt":"2026-06-29T13:24:33.234Z","slug":"CVE-2019-16202","body":"## Overview\n\nMISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a \"This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)\" message.\n\n## Affected\n\n- `misp < 2.4.115`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `misp 2.4.115`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}