CVE-2026-60125: importModule function in MISP ignores per-organisation import module restrictions

Published Jul 8, 2026
·
Updated

MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisation that was not allowed to use a module restricted via Plugin.Import<module>restrict could still invoke that import module directly if they knew its name.

This could allow unauthorised access to restricted import-module functionality and, depending on the module and the user’s event permissions, may allow unauthorised import or modification of event data through a module that should have been unavailable to the user’s organisation.

Affected Software

1 affected component
MISP

Event History

Jul 8, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-60125?

The severity of CVE-2026-60125 is medium with a CVSS score of 5.3.

2

How do I fix CVE-2026-60125?

To fix CVE-2026-60125, ensure that the importModule function correctly enforces per-organisation import module restrictions during module lookups.

3

What software is affected by CVE-2026-60125?

The software affected by CVE-2026-60125 is MISP.

4

What type of vulnerability is CVE-2026-60125?

CVE-2026-60125 is a vulnerability related to improper enforcement of module restrictions within the MISP platform.

5

Who is impacted by CVE-2026-60125?

Authenticated users from organizations that are restricted from using certain modules may be impacted by CVE-2026-60125.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-60125 - importModule function in MISP ignores per-organisation import module restrictions - SecAlerts