CVE-2026-107278
Deferred Deferred - Pending Action

Validation Bypass in MISP Object Sync Leading to Data Loss

Vulnerability report for CVE-2026-107278, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: CIRCL

Description

MISP contains a validation flaw in its object synchronization logic. When a MISP Object is created without a description, it is stored correctly on the originating instance. However, when that object is replicated to another MISP instance via the sync mechanism, the receiving instance's validation rule rejects the object because the description field is empty. As a result, the receiving instance silently drops the object along with all of its associated attributes, leading to loss of threat-intelligence data. Preconditions: - Two or more MISP instances are configured to synchronize objects. - A user with object-creation privileges creates an object without supplying a description. - The object is subsequently synced to a peer instance. Impact: - Valid objects and their attributes are silently discarded on receiving instances, causing data-integrity loss in the threat-intelligence pipeline. - The issue is not externally exploitable in a traditional sense but can be triggered by any authorized user who creates objects without descriptions, resulting in unintended data loss across the sync topology. Affected: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MISP MISP 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a flaw in how it handles object synchronization. When an object is created without a description on one instance, it syncs correctly to the originating server. However, when this object is replicated to another MISP instance, the receiving instance rejects it due to the missing description. This causes the object and all its attributes to be silently dropped, resulting in loss of shared threat intelligence data.

Detection Guidance

Check MISP instance logs for sync failures or dropped objects during synchronization. Look for entries where objects with missing descriptions are rejected by peer instances.

Impact Analysis

If you rely on MISP for sharing threat intelligence across multiple instances, this vulnerability could cause you to lose critical data. Objects and their attributes may disappear without warning when synced between instances, disrupting your threat detection and response workflows.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR and HIPAA by causing unintended loss of threat-intelligence data during synchronization between MISP instances. If critical threat data is dropped due to missing descriptions, organizations may fail to maintain required data integrity or availability for audits or incident response.

Mitigation Strategies

Upgrade all MISP instances to version 2.5.48 or later to address the validation flaw. Ensure all objects include descriptions before synchronization to prevent data loss.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107278. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart