VYPR
Medium severityNVD Advisory· Published Sep 15, 2026

CVE-2026-91851

CVE-2026-91851

Description

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag.

DashboardsController::listTemplates() allowed a template when either:

  • its restrict_to_permission_flag matched one of the current user’s permission flags, or
  • restrict_to_permission_flag equaled integer 0

However, restrict_to_permission_flag is a varchar. MySQL therefore performed numeric coercion when comparing the column against integer 0. Strings such as perm_site_admin convert numerically to zero, making expressions such as perm_site_admin = 0 evaluate true and causing the “unrestricted” branch to match permission-restricted templates as well.

Version affected: ≤2.5.45

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.