MISP 在事件扁平化(event flattening)功能中存在一个授权绕过漏洞。当用户请求启用 选项的事件时,应用程序会从查询中移除 Object(对象)的包含关系,并将对象的属性作为顶层事件属性返回。在此过程中,原本应用于这些属性的对象级别分发(distribution)和共享组(sharing-group)访问控制检查未被重新应用。 因此,能够查看社区分发(community-distributed)事件的用户,可以获取属于仅限组织内部访问的对象(distribution 级别为 0)或受特定共享组限制的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103655 | 9.3 CRITICAL | MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period |
| CVE-2026-103651 | 7.6 HIGH | MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authenticatio |
| CVE-2026-103858 | 5.3 MEDIUM | MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussio |
| CVE-2026-103662 | 5.1 MEDIUM | MISP Reflected XSS in Taxonomy Tag Confirmation Forms |
| CVE-2026-103664 | 4.8 MEDIUM | MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter |
No comments yet