---
id: CVE-2026-104912
title: >-
  MISP contains an authorization flaw in its correlation handling during
  attribute searches
summary: >-
  MISP contains an authorization flaw in its correlation handling during
  attribute searches. When a user performs an attribute search that triggers
  correlation lookups, the system authorized access to correlated attributes and
  events based…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-284
  - CWE-862
vendor: MISP
product: MISP
affected:
  - MISP < 2.5.48
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T16:16:49.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104912'
references:
  - url: 'https://github.com/MISP/MISP/commit/100235bd9'
    label: 5a6e4751-2f3f-4070-9419-94fb35b644e8
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T16:22:59.530Z'
---

## Overview

MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.

Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.

Preconditions:

- An authenticated user with at least read access to some events in the instance.

- The existence of correlations between events, at least one of which has been restricted after the correlation was created.

Impact:

- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.

Affected versions: MISP prior to v2.5.48.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
