CVE-2026-104910
Deferred Deferred - Pending Action

Authorization Bypass in MISP Event Correlation

Vulnerability report for CVE-2026-104910, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event. The correlation table stores a snapshot of the event's distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to openβ€”because they are unpublished, or because their distribution or sharing group has changed since the correlation was recordedβ€”were still returned with their metadata (title, date, correlating value counts). Preconditions: - An authenticated user with access to at least one event in MISP. - The existence of correlation entries linking that event to other events the user should not be able to view. Impact: - Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access. - Potential reconnaissance of threat-intelligence event names and timelines across sharing groups. Affected: MISP versions prior to the fix commit (2ffa97f05).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.11.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an authorization bypass in the related events listing feature. When a user requests correlated events for a given event, the system retrieves metadata from the correlation table without rechecking if the user has access to each related event. The correlation table stores outdated distribution and sharing group data, so events the user cannot viewβ€”due to unpublished status or changed permissionsβ€”are still returned with metadata like titles, dates, and correlation counts.

Impact Analysis

An authenticated user could see metadata of events they are not authorized to access. This includes event titles, dates, and correlation counts, potentially revealing sensitive threat-intelligence information across sharing groups. The impact is limited to information disclosure, not data modification or deletion.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive event data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected MISP versions may fail compliance audits due to improper access controls exposing protected information.

Mitigation Strategies

Update MISP to the latest version that includes the fix commit 2ffa97f05. This patch modifies the related event listing functions to enforce proper access control by validating caller permissions against each event's metadata and published status.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104910. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart