Description
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls.


The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature.

The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently.




Version affected: ≤2.5.45
Published: 2026-09-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure through Improper Authorization
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by missing authorization checks in the freetext feed preview feature of MISP. The preview performs correlation lookups against event attributes without respecting the requesting user’s ACL. As a result, an attacker who can access the preview API can see events, attributes, and object data that they should not be able to view, as well as correlation results that reference restricted feeds. Additionally, the preview returns the feed URLs for feeds that should not be disclosed, exposing additional metadata. The flaw is categorized as the authorization weakness CWE‑862.

Affected Systems

The flaw exists in MISP MISP version 2.5.45 and earlier. The affected product is the MISP event correlation and feed preview module, which is used by organizations to visualise relationships between attack-related data. Users of these versions are able to call the preview endpoint for freetext feeds and may be granted unexpected visibility into restricted event content and feed details.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. There is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is currently unexploited or not widely reported. An attacker could exploit the flaw by sending authenticated or unauthenticated requests to the preview API, provided they have network access to the MISP instance. Because the exploit requires no special privileges beyond the ability to reach the preview endpoint, the risk of accidental exposure is moderate; however, the information leaked could be sensitive to the organization’s security posture.

Generated by OpenCVE AI on September 7, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MISP to a version newer than 2.5.45 that includes the authorization fix.
  • Restrict preview API access to privileged users by adjusting role permissions in MISP.
  • Review and adjust feed visibility settings to ensure that only authorized feeds are set to `lookup_visible`, reducing metadata exposure.

Generated by OpenCVE AI on September 7, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Misp-project
Misp-project misp
CPEs cpe:2.3:a:misp-project:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp-project
Misp-project misp
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Mon, 07 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls. The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently. Version affected: ≤2.5.45 Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls. The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently. Version affected: ≤2.5.45

Mon, 07 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls. The same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature. The fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently. Version affected: ≤2.5.45
Title MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Information
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-08T14:48:31.530Z

Reserved: 2026-09-07T09:02:53.939Z

Link: CVE-2026-86342

cve-icon Vulnrichment

Updated: 2026-09-08T14:48:28.368Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T09:17:17.943

Modified: 2026-09-09T15:22:56.660

Link: CVE-2026-86342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses