← Back to CVE List
CVE-2026-104912NVD
Vulnerability Summary
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.
Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.
Preconditions:
- An authenticated user with at least read access to some events in the instance.
- The existence of correlations between events, at least one of which has been restricted after the correlation was created.
Impact:
- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.
Affected versions: MISP prior to v2.5.48.
Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.
Preconditions:
- An authenticated user with at least read access to some events in the instance.
- The existence of correlations between events, at least one of which has been restricted after the correlation was created.
Impact:
- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.
Affected versions: MISP prior to v2.5.48.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- MISP MISP < 2.5.48
- MISP MISP 2.5.48