Description
MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event.

The correlation table stores a snapshot of the event's distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts).

Preconditions:

- An authenticated user with access to at least one event in MISP.

- The existence of correlation entries linking that event to other events the user should not be able to view.

Impact:

- Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.

- Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.

Affected: MISP versions prior to the fix commit (2ffa97f05).
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability in MISP occurs during the retrieval of related events for a given event. Instead of verifying each related event against the user's current access rights, the system uses a snapshot stored in the correlation table that lacks published status and can be out of date regarding distribution level or sharing group membership. As a result, an authenticated user can receive metadata—such as titles, dates, and correlation counts—for events they are not allowed to view, allowing reconnaissance of threat‑intelligence information across groups and potentially revealing sensitive event names and timelines.

Affected Systems

MISP products are affected. Any installation of MISP that has not incorporated the fix commit (2ffa97f05) is vulnerable. The fix changes the query logic to apply the full set of authorization checks when constructing the related events list.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity for information disclosure. No EPSS score is available, so the likelihood of immediate exploitation is unclear, but the vulnerability is present in authenticated users who have at least one accessible event and that event is linked to others the user should not see. Because the exploit requires only legitimate credentials and no further privileges, the attack vector can be considered user‑controlled. The vulnerability is not listed in CISA’s KEV catalog at this time, yet the potential for accidental or intentional exposure of event metadata remains a concern for organizations using MISP for threat intelligence sharing.

Generated by OpenCVE AI on October 2, 2026 at 17:38 UTC.

Remediation

Vendor Solution

The fix enforces proper per-event authorization on the related events query by applying the user's full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.


OpenCVE Recommended Actions

  • Apply the vendor patch that updates the related events lookup to enforce per‑event authorization.
  • After patching, run a scan of all correlation tables to verify that only events the user is currently permitted to view are returned in the related events list.
  • Review configured distribution levels, sharing groups, and published flags for existing events to ensure that visibility rules correctly reflect current access policies; adjust these settings if necessary to prevent future exposure of sensitive metadata.

Generated by OpenCVE AI on October 2, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event. The correlation table stores a snapshot of the event's distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts). Preconditions: - An authenticated user with access to at least one event in MISP. - The existence of correlation entries linking that event to other events the user should not be able to view. Impact: - Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access. - Potential reconnaissance of threat-intelligence event names and timelines across sharing groups. Affected: MISP versions prior to the fix commit (2ffa97f05).
Title MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CWE-862
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:01:32.781Z

Reserved: 2026-10-02T16:01:26.599Z

Link: CVE-2026-104910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.813

Modified: 2026-10-02T16:16:48.920

Link: CVE-2026-104910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses