CVE-2026-104912
Deferred Deferred - Pending Action

Authorization Bypass in MISP via Stale Correlation Data

Vulnerability report for CVE-2026-104912, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an authorization flaw in its correlation handling during attribute searches. When a user searches attributes that trigger correlation lookups, the system uses a stale distribution snapshot stored on the correlation row instead of the live event access control list to authorize access. This stale data lacks a published flag and becomes outdated if an event is later restricted, allowing unauthorized access to restricted event information.

Detection Guidance

To detect this vulnerability, check MISP logs for unauthorized attribute or event access during correlation searches. Review the `runGetRelatedAttributes` and `fetchRelatedEventIds` functions for stale distribution checks. Ensure the `__filterVisibleEventIds` method is correctly filtering events based on user permissions.

Impact Analysis

An authenticated user with read access could retrieve attributes and event details they are no longer authorized to view. This happens when correlations exist between events, and at least one event is restricted after the correlation was created, exposing confidential information.

Compliance Impact

This vulnerability could lead to unauthorized exposure of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Unauthorized access to restricted event information may result in non-compliance with data protection regulations.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to apply the security fix. Verify that correlations now use live event access control lists instead of stale distribution snapshots. Audit recent attribute searches for unauthorized access and restrict affected events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104912. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart