CVE-2026-107175
Deferred Deferred - Pending Action

Information Disclosure in MISP Event Correlation Engine

Vulnerability report for CVE-2026-107175, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: CIRCL

Description

MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted. Security impact: - Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure. - Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing. Preconditions: - An authenticated user with write access to at least one MISP event. - The user modifies the event's distribution or sharing_group_id field. Affected versions: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MISP MISP 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-665 The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a flaw in its event save process where changing an event's distribution level or sharing group does not trigger a recalculation of correlations. The system fails to compare old and new values properly, leaving stale correlations that may expose data incorrectly or miss relevant threat intelligence.

Detection Guidance

This vulnerability is specific to MISP event editing and correlation updates. Detection requires checking MISP event logs for distribution or sharing group modifications that did not trigger correlation recalculations. Review the commit fix in Resource 1 for implementation details.

Impact Analysis

If you edit an event and change its sharing settings, sensitive data might remain visible to users who should no longer have access. Alternatively, important correlations may not appear, reducing the effectiveness of threat intelligence sharing.

Compliance Impact

This could lead to unauthorized data exposure, violating principles of data minimization and access control required by GDPR and HIPAA. Unintended sharing of sensitive event data may result in non-compliance.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to address the defect. The fix ensures correlation updates occur when distribution or sharing group changes are made. Verify the fix by testing event edits and confirming correlation recalculations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107175. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart