THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86418 (MEDIUM 4.3) — Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including:  - organisati

[NVD] CVE-2026-86418 (MEDIUM 4.3) — Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including:  - organisati

mednvdPublished 2026-09-07

CVE-2026-86418 CVSS: 4.3 MEDIUM Published: 2026-09-07T13:20:40.527

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view.

The affected endpoint returned fields including:

 - organisation ID;

 - UUID;

 - name.

When Security.hide_

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86418