CVE-2026-90955
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLogable behavior stored that identity in behavior-instance state that could be overwritten when another model lazily attached the shared behavior. Consequently, subsequent CLI writes could lose the intended user attribution and be logged incorrectly. The commit also notes that CLI-originated records lacked a CLI marker, making them appear similar to ordinary web actions by that user. Version affected: ≤2.5.45
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-778, CWE-223
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- MISP MISP
Weakness type
Related vulnerabilities
- CVE-2024-48967 — Life2000 ventilator and Service PC lack sufficient audit logging capabilities
- CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-32967 — OpenEMR doesn't log password administration properly
- CVE-2023-1995 — Insufficient Logging Vulnerability in HiRDB