Description
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.

When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.

Preconditions:

- An authenticated MISP user with at least read access to an event owned by another organization.

- The user issues a query for deleted attributes (search or paginated view with the deleted filter).

Impact:

- Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility.

Affected versions: MISP versions prior to v2.5.48.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of soft‑deleted threat intelligence
Action: Immediate Patch
AI Analysis

Impact

An improper access control flaw in MISP’s attribute search and paginated view endpoints allows an authenticated user to retrieve soft‑deleted attributes that belong to events owned by other organizations. When a user searches for deleted attributes or views the paginated list with the deleted filter, the application returns all soft‑deleted attributes associated with events their account can read, regardless of the event’s owning organization. This results in the confidential threat intelligence—such as IOCs or contextual information—that the owner intended to remove becoming visible to unauthorized users.

Affected Systems

Vulnerable versions are all releases of MISP prior to v2.5.48. The issue affects the MISP:MISP product in any deployment where users have read access to events owned by other organizations and where the attribute search or paginated view interfaces are exposed to those users.

Risk and Exploitability

The flaw permits confidentiality disclosure; it does not lead to code execution or denial of service. CVSS indicates a medium severity of 5.3. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation may not yet be widespread. The likely attack vector is any authenticated user within the MISP environment who has read access to another organization’s event and who can submit a query for deleted attributes. Exploitation requires no special privileges beyond ordinary event read access.

Generated by OpenCVE AI on October 2, 2026 at 18:05 UTC.

Remediation

Vendor Solution

The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user's organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.


OpenCVE Recommended Actions

  • Upgrade MISP to version v2.5.48 or later, which enforces organization ownership checks on soft‑deleted attribute queries.
  • Modify configuration or permissions so that users without sync permission cannot request deleted attributes via the search or paginated view interfaces.
  • Audit existing read‑only permissions to ensure that only authorized organizations’ members can see soft‑deleted attributes, and review sync‑permission settings to restrict cross‑organization visibility.

Generated by OpenCVE AI on October 2, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.
Title MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View
First Time appeared Misp
Misp misp
Weaknesses CWE-284
CWE-862
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:09:40.333Z

Reserved: 2026-10-02T16:09:36.435Z

Link: CVE-2026-104914

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:49.280

Modified: 2026-10-02T16:16:49.390

Link: CVE-2026-104914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:15:13Z

Weaknesses