A vulnerability described as problematic has been identified in MISP cti-transmute up to 1.4.0. This affects the function build_evaluation_report of the component Report Builder. Such manipulation leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-73140. The attack can be launched remotely. No exploit exists.

It is best practice to apply a patch to resolve this issue.