THREAT OPS › Threat News › [NVD] CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs thr
[NVD] CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs thr
CVE-2026-86283 CVSS: None Published: 2026-09-06T15:17:24.813
MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces
Indicators of compromise
- CVE-2026-86283cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86283