{"id":"CVE-2026-104912","title":"MISP contains an authorization flaw in its correlation handling during attribute searches","summary":"MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-284","CWE-862"],"vendor":"MISP","product":"MISP","affected":["MISP < 2.5.48"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T16:16:49.163","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104912","references":[{"url":"https://github.com/MISP/MISP/commit/100235bd9","label":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-02T16:22:59.530Z","slug":"CVE-2026-104912","body":"## Overview\n\nMISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}