MISP 在“相关事件列表”功能中存在授权绕过漏洞。当用户请求获取与某一给定事件相关联的事件列表时,系统直接从关联表中检索相关事件的元数据,而未针对每个相关事件重新验证调用者的访问权限。 关联表在创建关联时,会保存该事件的共享级别(distribution level)和共享组(sharing group)的快照,且不包含“已发布”(published)标志位。因此,即使用户无权访问某些事件(例如这些事件尚未发布,或自关联记录创建以来其共享级别或共享组已发生变更),系统仍会返回这些事件的元数据(包括标题、日期及相关
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104908 | 7.1 HIGH | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D |
| CVE-2026-104912 | 7.1 HIGH | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data |
| CVE-2026-104906 | 6.2 MEDIUM | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
| CVE-2026-104900 | 5.3 MEDIUM | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
| CVE-2026-104914 | 5.3 MEDIUM | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa |
| CVE-2026-104901 | 5.1 MEDIUM | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Serv |
| CVE-2026-104907 | 4.8 MEDIUM | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
No comments yet