Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107175— MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 的事件保存工作流中存在一个缺陷,导致在修改事件的“分发级别”或“共享组”后,相关性引擎无法重新计算事件间的相关性。 当用户编辑现有事件并更改其分发级别或 sharing_group_id 时,内部保存前钩子(before-save hook)存储的是传入的新数据,而非之前持久化的旧值。因此,用于判断是否需要刷新相关性的保存后比较机制无法检测到该变更,导致过时(stale)的相关性数据得以保留。 安全影响: 在事件被移至更严格的共享组后,过时的相关性可能继续向属于更广泛共享组的用户暴露事件数据,从而导致非预

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1074 · Data Staged
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107175

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted. Security impact: - Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure. - Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing. Preconditions: - An authenticated user with write access to at least one MISP event. - The user modifies the event's distribution or sharing_group_id field. Affected versions: <2.5.48
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-107175

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107175

请登录查看更多情报信息。

Other References for CVE-2026-107175 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107175

No comments yet


Leave a comment