VYPR
High severityNVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026

CVE-2026-104912

CVE-2026-104912

Description

MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.

Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.

Preconditions:

  • An authenticated user with at least read access to some events in the instance.
  • The existence of correlations between events, at least one of which has been restricted after the correlation was created.

Impact:

  • Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.

Affected versions: MISP prior to v2.5.48.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.