CVE-CVE-2026-86283
Severity
UNKNOWN
CVSS Score
0.0
Description
MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces per-user event ACL. However, the view template independently re-queried the same UUIDs using only an Event.uuid IN (...) condition, omitting the createEventCondit...
PoCs for CVE-CVE-2026-86283
sentric-core
General
0
Freire007-byte
2026-09-13