CVE-2026-9136: Unauthorized ShadowAttribute modification in MISP via client-supplied identifier

Published May 20, 2026
·
Updated

A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an instruction to update an existing record, an authenticated user able to submit shadow attribute proposals could provide the identifier of an existing ShadowAttribute and cause that record to be updated instead of creating a new proposal.

This can result in unauthorized modification of existing shadow attributes, potentially affecting proposals associated with events the user should not be able to alter. Depending on deployment configuration and accessible API responses, the issue may also expose or move proposal data across event contexts.

The vulnerability is caused by trusting a client-supplied primary key during object creation. The fix removes the id field from incoming ShadowAttribute data before processing, ensuring that the endpoint always creates a new proposal rather than updating an existing one. This has been fixed in MISP 2.5.38.

Affected Software

2 affected components
Misp Project Misp<2.5.38
Misp-project Misp>=2.5.0<2.5.38

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in 2.5.38
  2. Configuration

    Update the ShadowAttribute add/proposal creation workflow to remove the user-supplied id field from incoming ShadowAttribute request data before processing so the endpoint always creates a new proposal instead of updating an existing record.

    MISP ShadowAttribute proposal creation endpoint remove id from incoming ShadowAttribute request data before saving = id removed

Event History

May 20, 2026
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9136?

The severity of CVE-2026-9136 is classified as high due to potential unauthorized modifications to ShadowAttributes.

2

How do I fix CVE-2026-9136?

To fix CVE-2026-9136, upgrade your MISP instance to version 2.5.39 or later, which addresses this vulnerability.

3

What does CVE-2026-9136 affect?

CVE-2026-9136 affects MISP versions prior to 2.5.39, allowing unauthorized modifications via client-supplied identifiers.

4

Who is impacted by CVE-2026-9136?

Organizations using MISP versions prior to 2.5.39 are at risk from CVE-2026-9136.

5

What is the exploit mechanism for CVE-2026-9136?

The exploit mechanism for CVE-2026-9136 involves the submission of user-controlled data that can manipulate ShadowAttributes without proper validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203