Description
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.

Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.

Preconditions:

- An authenticated user with at least read access to some events in the instance.

- The existence of correlations between events, at least one of which has been restricted after the correlation was created.

Impact:

- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.

Affected versions: MISP prior to v2.5.48.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized confidentiality exposure via authorization bypass
Action: Patch Now
AI Analysis

Impact

An authorization flaw exists in MISP’s correlation handling during attribute searches. When a user initiates a search that triggers correlation lookups, the system authorizes access to related events and attributes based on a stale distribution snapshot stored on the correlation row instead of the live event access‑control list. This allows an authenticated user to retrieve the values and metadata of attributes belonging to events they no longer have permission to view, compromising confidentiality.

Affected Systems

All MISP installations running versions prior to 2.5.48 are affected. The vulnerability targets the correlation module used for attribute searches in the open‑source threat‑intelligence platform.

Risk and Exploitability

The flaw can only be exploited by authenticated users possessing at least read access to some events. Once credentials are available, an attacker can trigger correlation lookups through the web UI or API, directly retrieving restricted event and attribute data. With a CVSS score of 7.1 the severity is high; the EPSS is not available, and the vulnerability is not listed in KEV, indicating no widespread exploitation yet but still representing a moderate‑to‑high risk until a patch is applied.

Generated by OpenCVE AI on October 2, 2026 at 17:36 UTC.

Remediation

Vendor Solution

The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.


OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.48 or later, which implements live ACL checks for correlation lookups and removes sensitive metadata from attribute responses.
  • If an upgrade cannot be performed immediately, disable the correlation feature for non‑admin users or restrict correlation queries until the fix is deployed.
  • After applying the patch, audit recent correlation searches against restricted events to confirm that live ACL enforcement is functioning correctly.

Generated by OpenCVE AI on October 2, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48.
Title MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
First Time appeared Misp
Misp misp
Weaknesses CWE-284
CWE-862
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:04:50.580Z

Reserved: 2026-10-02T16:04:47.753Z

Link: CVE-2026-104912

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:49.047

Modified: 2026-10-02T16:16:49.163

Link: CVE-2026-104912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:45:17Z

Weaknesses