CVE-2026-104912High· 7.1▾ TwilightMISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.
Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.
Preconditions:
An authenticated user with at least read access to some events in the instance.
The existence of correlations between events, at least one of which has been restricted after the correlation was created.
Impact:
Affected versions: MISP prior to v2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104914Medium· 5.3MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute l…
CVE-2026-103239High· 8.6MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality
CVE-2026-104910Medium· 5.3MISP contains an authorization bypass in the related events listing functionality
CVE-2026-103659High· 7.1MISP contains an authorization bypass in the event flattening feature
CVE-2026-95683Medium· 5.3In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes
CVE-2026-95685Medium· 5.3MISP contains an access control flaw in the EventReports functionality