Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104912— MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 在属性搜索过程中的关联处理存在授权缺陷。当用户执行触发关联查找的属性搜索时,系统基于存储在关联行中的过时的分布快照(而非实时的事件访问控制列表)来授权访问关联的属性及事件。 由于关联行中的分布列是某个时间点的静态副本,且不包含“已发布”状态标志,当事件后续被限制访问(例如,其共享组被更改或事件被取消发布)时,授权检查机制将失效。因此,经过身份验证的用户可能能够检索到他们已无权查看的事件所关联的属性及事件详情。 前提条件: 用户已通过身份验证,并且至少对实例中的部分事件拥有只读权限。 事件之间存在关联,且至

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104912

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-104912

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104912

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104912 (1)

Same Patch Batch · MISP · 2026-10-02 · 8 CVEs total

CVE-2026-104908 7.1 HIGH MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D
CVE-2026-104906 6.2 MEDIUM MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
CVE-2026-104900 5.3 MEDIUM MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index
CVE-2026-104910 5.3 MEDIUM MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
CVE-2026-104914 5.3 MEDIUM MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa
CVE-2026-104901 5.1 MEDIUM MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Serv
CVE-2026-104907 4.8 MEDIUM MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler

IV. Related Vulnerabilities

V. Comments for CVE-2026-104912

No comments yet


Leave a comment