Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.
Preconditions:
- An authenticated user with at least read access to some events in the instance.
- The existence of correlations between events, at least one of which has been restricted after the correlation was created.
Impact:
- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.
Affected versions: MISP prior to v2.5.48.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/100235bd9 |
|
Fri, 02 Oct 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48. | |
| Title | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-284 CWE-862 |
|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-02T16:04:50.580Z
Reserved: 2026-10-02T16:04:47.753Z
Link: CVE-2026-104912
No data.
Status : Deferred
Published: 2026-10-02T16:16:49.047
Modified: 2026-10-02T16:16:49.163
Link: CVE-2026-104912
No data.
OpenCVE Enrichment
Updated: 2026-10-02T18:45:17Z