---
id: CVE-2019-9482
title: >-
  In MISP 2.4.102, an authenticated user can view sightings that they should not
  be eligible for
summary: >-
  In MISP 2.4.102, an authenticated user can view sightings that they should not
  be eligible for. Exploiting this requires access to the event that has
  received the sighting. The issue affects instances with restrictive sighting
  settings (…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: misp-project
product: misp
affected:
  - misp = 2.4.102
published: '2019-03-01'
updated: '2026-06-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-9482'
references:
  - url: >-
      https://github.com/MISP/MISP/commit/c69969329d197bcdd04832b03310fa73f4eb7155
    label: cve@mitre.org
  - url: >-
      https://github.com/MISP/MISP/commit/c69969329d197bcdd04832b03310fa73f4eb7155
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00868
epssPercentile: 0.56725
ingestedAt: '2026-06-29T13:24:33.226Z'
---

## Overview

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

## Affected

- `misp = 2.4.102`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
