CVE-2026-86283 is an authorization bypass in MISP's UiBeta collection-view functionality. Although the controller resolves collection member events using the requesting user's event-level ACL, the presentation layer performs a separate lookup of member event UUIDs without applying the corresponding authorization conditions. Collection elements can reference event UUIDs without server-side validation that the collection owner is authorized to access the referenced event. Consequently, an authenticated user authorized to view a collection can cause the UiBeta view to return details for referenced events outside that user's event-level access scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a 13-file Python-based SENTRIC automation repository rather than a dedicated exploit-framework module. Its primary exploit artifacts are the near-duplicate lab_pocs/CVE-2026-86283.py and CVE-2026-86283.manual.py scripts. They target a MISP collection-element authorization flaw: using a supplied MISP administrative API key, they build two isolated organizations and a private victim event; they then log in as a normal user in the attacker organization, attempt to add the victim event UUID to an attacker collection, and check whether the private event marker is rendered. The scripts accept the target through LAB_URL, disable TLS certificate verification, retain redirects on the configured target origin, and write the viewed collection to /tmp/sentric_view.html. The accompanying report says the isolated test at https://172.18.0.4 was INCONCLUSIVO and captured no leak, so the repository does not provide evidence that the claimed CVE is confirmed. sentric_lab.py is a Docker-based validation harness that provisions a MISP 2.5.45 lab with MySQL and Redis, bootstraps MISP administrative access, generates/runs PoCs, and writes reports. The rest of the repository implements unrelated broader automation: sentric_core.py manages a Solana wallet, NVD-based CVE triage, local-LLM calls, market data, and staking/trading state; sentric_zero.py scores CVE opportunities and searches GitHub for public PoCs; sentric_bridge.py reports triage data to a local FastAPI service; and sentric_trader.py can, when invoked with --live, sign and submit SOL/USDC swaps through Jupiter and Solana RPC. These non-PoC components materially expand the repository's network and financial capabilities but are not required for the MISP disclosure test.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.