THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs thr

[NVD] CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs thr

mednvdPublished 2026-09-06

CVE-2026-86283 CVSS: None Published: 2026-09-06T15:17:24.813

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86283