CVE-2026-94394
Deferred Deferred - Pending Action

Information Disclosure in MISP Event References

Vulnerability report for CVE-2026-94394, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: CIRCL

Description

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level. The vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data. The main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 5a6e4751-2f3f-4070-9419-94fb35b644e8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in MISP allows authenticated users with event access to view restricted attributes or objects within that event. The issue occurs because MISP checks event-level permissions but not individual data restrictions when adding references between objects or attributes. This means users may see sensitive data meant for specific sharing groups or distribution levels.

Detection Guidance

To detect this vulnerability, review MISP logs for unauthorized access attempts to restricted attributes or objects. Check for users accessing events where they lack proper permissions. Use MISP's built-in audit logs to track reference additions and verify if restrictions are enforced correctly.

Impact Analysis

If you are an authenticated MISP user without admin rights, you could access sensitive attribute values, object details, or related data in events you can view but should not have permission to see. This includes data restricted to specific sharing groups or distribution levels.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements like GDPR or HIPAA. Unauthorized exposure of restricted data may result in legal penalties, loss of trust, or regulatory fines due to inadequate data protection measures.

Mitigation Strategies

Apply the latest MISP security patch from the provided commit. Ensure all users have appropriate sharing group and distribution level permissions. Review and update event-level and attribute-level access controls to enforce granular restrictions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94394. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart