Impact
The vulnerability is caused by missing authorization checks in the freetext feed preview feature of MISP. The preview performs correlation lookups against event attributes without respecting the requesting user’s ACL. As a result, an attacker who can access the preview API can see events, attributes, and object data that they should not be able to view, as well as correlation results that reference restricted feeds. Additionally, the preview returns the feed URLs for feeds that should not be disclosed, exposing additional metadata. The flaw is categorized as the authorization weakness CWE‑862.
Affected Systems
The flaw exists in MISP MISP version 2.5.45 and earlier. The affected product is the MISP event correlation and feed preview module, which is used by organizations to visualise relationships between attack-related data. Users of these versions are able to call the preview endpoint for freetext feeds and may be granted unexpected visibility into restricted event content and feed details.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. There is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is currently unexploited or not widely reported. An attacker could exploit the flaw by sending authenticated or unauthenticated requests to the preview API, provided they have network access to the MISP instance. Because the exploit requires no special privileges beyond the ability to reach the preview endpoint, the risk of accidental exposure is moderate; however, the information leaked could be sensitive to the organization’s security posture.
OpenCVE Enrichment