CVE-2026-104914Medium· 5.3▾ SunlitMISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute l…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.
When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.
Preconditions:
An authenticated MISP user with at least read access to an event owned by another organization.
The user issues a query for deleted attributes (search or paginated view with the deleted filter).
Impact:
Affected versions: MISP versions prior to v2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104912High· 7.1MISP contains an authorization flaw in its correlation handling during attribute searches
CVE-2026-103239High· 8.6MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality
CVE-2026-104910Medium· 5.3MISP contains an authorization bypass in the related events listing functionality
CVE-2026-103659High· 7.1MISP contains an authorization bypass in the event flattening feature
CVE-2026-95683Medium· 5.3In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes
CVE-2026-95685Medium· 5.3MISP contains an access control flaw in the EventReports functionality