CVE-2026-104914
Deferred Deferred - Pending Action

Improper Access Control in MISP Attribute Search

Vulnerability report for CVE-2026-104914, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an improper access control flaw where soft-deleted attributes from events owned by other organizations are exposed to unauthorized authenticated users. This happens during attribute searches or paginated views when querying for deleted items. The event detail view correctly restricts access, but the search and listing endpoints lack this restriction.

Detection Guidance

Check MISP logs for queries involving deleted attributes or paginated attribute views. Look for unauthorized access attempts to event data not owned by the querying user. Review user activity logs for suspicious searches filtering on soft-deleted attributes.

Impact Analysis

If you are an authenticated MISP user with read access to an event owned by another organization, you could view soft-deleted threat intelligence data (like IOCs or indicators) from that event. This may expose sensitive intelligence that the owning organization intended to remove.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations using MISP may face compliance risks if soft-deleted data containing personal or health information is exposed.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to apply the security patch. Review and restrict user permissions to ensure only authorized personnel can access sensitive event data. Monitor attribute searches and paginated views for unauthorized access patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104914. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart