Description
MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified.

When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted.

Security impact:

- Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure.

- Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing.

Preconditions:

- An authenticated user with write access to at least one MISP event.

- The user modifies the event's distribution or sharing_group_id field.

Affected versions: <2.5.48
Published: 2026-10-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unintended Information Disclosure
Action: Apply Patch
AI Analysis

Impact

MISP’s event save workflow incorrectly stores the new distribution and sharing group values instead of the previously persisted ones, causing the correlation engine to fail to detect changes. This flaw allows stale correlations to remain active after an event has been moved to a more restrictive sharing group, potentially exposing threat‑intelligence data to users who should no longer have access. The flaw also means new correlations may never surface when an event’s distribution is widened, decreasing the completeness of threat‑intelligence sharing. The weakness is rooted in improper initialization (CWE‑665) and improper access control (CWE‑284).

Affected Systems

The affected product is MISP, all releases older than 2.5.48. Any user with write access to an event can trigger the flaw if they modify the distribution or sharing_group_id fields.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, suggesting no publicly reported exploit data at this time. Because the flaw requires an authenticated user with write access, exploitation is limited to insiders or compromised credentials. The issue is not currently cataloged in the CISA KEV list, so it has not yet been exploited in the wild. However, once an attacker gains write access to an event, they can force unintended data exposure by altering its distribution or sharing group, making the vulnerability significant for organizations that share sensitive intelligence.

Generated by OpenCVE AI on October 7, 2026 at 14:55 UTC.

Remediation

Vendor Solution

The fix ensures that the before-save hook retrieves the previously persisted distribution and sharing_group_id values from the database for existing events, rather than capturing the incoming (new) data. This allows the after-save logic to correctly detect when these fields have changed and trigger a correlation refresh, ensuring access boundaries on correlated data are enforced promptly.


OpenCVE Recommended Actions

  • Apply the MISP 2.5.48 release or later, which includes the patch that restores correct before‑save logic for distribution and sharing group changes.
  • After upgrading, re‑run the correlation engine or manually trigger a refresh for existing events to clear any stale correlations.
  • Review all events that had distribution or sharing group changes while the old version was in use, and adjust their correlation data if necessary.

Generated by OpenCVE AI on October 7, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted. Security impact: - Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure. - Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing. Preconditions: - An authenticated user with write access to at least one MISP event. - The user modifies the event's distribution or sharing_group_id field. Affected versions: <2.5.48
Title MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
First Time appeared Misp
Misp misp
Weaknesses CWE-284
CWE-665
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-07T14:40:14.998Z

Reserved: 2026-10-07T12:38:41.839Z

Link: CVE-2026-107175

cve-icon Vulnrichment

Updated: 2026-10-07T14:40:10.583Z

cve-icon NVD

Status : Deferred

Published: 2026-10-07T13:17:20.563

Modified: 2026-10-07T15:17:19.377

Link: CVE-2026-107175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:00:07Z

Weaknesses