---
id: CVE-2026-103858
title: >-
  MISP contains an incomplete authorization check in the discussion posting
  functionality
summary: >-
  MISP contains an incomplete authorization check in the discussion posting
  functionality. When a user submits a post to a thread or replies to an
  existing post, the application only verified whether the target thread was
  restricted to a s…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-285
vendor: MISP
product: MISP
affected:
  - MISP >= unspecified < 2.5.48
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T12:17:16.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103858'
references:
  - url: 'https://github.com/MISP/MISP/commit/79fbd4c75'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T11:42:53.818Z'
---

## Overview

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.

As a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:

- Read the thread title and the content of the quoted post

- Submit a new post into the discussion thread

This constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).

Affected: <2.5.48

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
