CVE-2026-103659
Deferred Deferred - Pending Action

Authorization Bypass in MISP Event Flattening Feature

Vulnerability report for CVE-2026-103659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: CIRCL

Description

MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an authorization bypass in its event flattening feature. When a user requests an event with flattening enabled, the application removes object containment from the query and returns object attributes as top-level event attributes. This bypasses the original object-level distribution and sharing-group access control checks, allowing users to see attributes they are not permitted to access. For example, a user in a community event could retrieve attributes from organisation-only objects or objects restricted to specific sharing groups.

Detection Guidance

To detect this vulnerability, check if your MISP instance is running a version prior to 2.5.48. Review event flattening logs for unauthorized attribute access in community-distributed events. Look for users accessing attributes beyond their permission levels.

Impact Analysis

If you use MISP versions before 2.5.48, an attacker with access to a community-distributed event could exploit this to view sensitive threat intelligence data they should not have access to. This includes organisation-specific or sharing-group-restricted attributes, leading to unauthorized disclosure of confidential information. Additionally, a secondary issue could cause event owners to lose visibility of attributes if their parent object was soft-deleted, even if the attributes themselves were not deleted.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other data protection regulations by exposing sensitive threat intelligence data to unauthorized users. Unauthorized disclosure of restricted data violates principles of data minimisation, purpose limitation, and security under these regulations. Organisations using affected MISP versions may face legal and regulatory penalties for failing to protect sensitive information.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later immediately. Review and restrict access to community-distributed events. Audit event flattening logs for past unauthorized access. Ensure ACLs are properly enforced on flattened attributes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart