---
schema: 1
kind: vulnerability
title: "CVE-2026-10868 — MISP: critical mass-assignment account-takeover in the EU threat-sharing platform"
headline: "CVE-2026-10868 — MISP: critical mass-assignment account-takeover in the EU threat-sharing platform"
summary: "Critical account-takeover flaw in MISP (CVE-2026-10868, CVSS 9.0) — the threat-intel platform that underpins CERT-EU, GovCERT.ch and most EU national-CERT sharing; a mass-assignment bug lets an authenticated user edit another account (GitHub Security Advisory, 2026-06-04). Patched."
discovered_at: "2026-06-06T05:00:04Z"
event_date: 2026-06-04
run_id: 2026-06-06-d01b95fe
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - identity
  - auth-bypass
regions:
  - europe
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-10868
    cvss: "9.0"
    epss: null
    type: auth-bypass
    vector: local
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://github.com/advisories/GHSA-h7wj-m45x-884x"
    publisher: GitHub Security Advisory GHSA-h7wj-m45x-884x
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1800"
    publisher: BSI CERT-Bund WID-SEC-2026-1800
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch MISP instances to the 2026-06-04 release** (. Multi-org sharing hubs are highest-priority given the account-takeover + cross-org template-overwrite combination. Pre-patch, monitor `UsersController::edit` requests where the posted user id ≠ session user id."
migrated_from: briefs/2026-06-06.md
---

BSI published WID-SEC-2026-1800 covering seven vulnerabilities in MISP, the open-source threat-intelligence sharing platform that underpins CERT-EU, GovCERT.ch, CIRCL.lu and most EU national-CERT and ISAC feeds ([BSI CERT-Bund, 2026-06-04](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1800); [GitHub Security Advisory, 2026-06-04](https://github.com/advisories/GHSA-h7wj-m45x-884x)). The most severe, CVE-2026-10868 (CVSS 9.0), is a mass-assignment bug in `UsersController::edit()`: insufficient field filtering lets an authenticated user inject another account's identifier into the edit request, so the update is applied to an unintended account (`T1078` Valid Accounts / account manipulation) — an authenticated account-takeover and privilege-manipulation primitive. The other six (CVE-2026-10854/10855/10856/10860/10861/10864) cover access-control bypass on private galaxy metadata, an org-crossing event-template overwrite, and an open redirect. In a multi-organisation sharing hub the account-takeover combined with the cross-org template overwrite enables manipulation of the shared indicator pool itself. Patches shipped 2026-06-04; the CVE-2026-10868 fix explicitly strips the `User.id` field before edit processing. Detection concepts: review MISP access logs for `UsersController::edit` POSTs where the posted user id differs from the session user id, and audit user accounts for unexpected role/group attribute changes.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | n/a | n/a | No | Yes | None (mitigation only) | [Cisco PSIRT](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx) |
| CVE-2026-28318 | SolarWinds Serv-U (≤ 15.5.4) | 7.5 | n/a | Yes | Yes | 15.5.4 Hotfix 1 | [SolarWinds](https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318) |
| CVE-2026-10868 | MISP | 9.0 | n/a | No | No | Patched 2026-06-04 | [GHSA](https://github.com/advisories/GHSA-h7wj-m45x-884x) |
