Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104914— MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 在其属性搜索和分页属性查看端点中存在不适当的访问控制漏洞。 当用户查询软删除的属性(例如,通过“已删除属性”搜索或带有删除过滤器的分页属性列表)时,应用程序向任何对该事件具有可见性的已认证用户返回属于其他组织的事件的软删除属性。事件详情视图正确地限制了软删除属性的可见性,仅对拥有该事件的组织以及同步权限用户开放,但属性搜索和分页查看的代码路径缺少这一限制。 前提条件: 一个已认证的 MISP 用户,至少对另一个组织拥有的事件具有读取权限。 该用户发起了对已删除属性的查询(搜索或使用删除过滤器的分页视图)。

CVSS 5.3 · Medium EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP MISP < 2.5.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104914

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-104914

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104914

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104914 (1)

Other References for CVE-2026-104914 (1)

Same Patch Batch · MISP · 2026-10-02 · 8 CVEs total

CVE-2026-104908 7.1 HIGH MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and D
CVE-2026-104912 7.1 HIGH MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
CVE-2026-104906 6.2 MEDIUM MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
CVE-2026-104900 5.3 MEDIUM MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index
CVE-2026-104910 5.3 MEDIUM MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
CVE-2026-104901 5.1 MEDIUM MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Serv
CVE-2026-104907 4.8 MEDIUM MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler

IV. Related Vulnerabilities

V. Comments for CVE-2026-104914

No comments yet


Leave a comment