high · CVSS v3 4.3 · CVSS v4 7.1
CVE-2026-104912
MISP before v2.5.48 has an authorization flaw in correlation handling during attribute searches. Correlated attributes and events can be aut
Overview
MISP before v2.5.48 has an authorization flaw in correlation handling during attribute searches. Correlated attributes and events can be authorized using a stale distribution snapshot instead of the live event access control list. This matters because restricted or unpublished events may remain visible to authenticated users who no longer have permission.
Description
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48.
Impact
Confidentiality is affected: authenticated users with read access to some events may retrieve attribute values and event metadata from events they no longer can access. Integrity and availability are not described as directly impacted. Impact is limited to users who can trigger attribute searches that perform correlation lookups in instances with stale correlations. Defenders should treat this as unauthorized disclosure of MISP event and attribute data.
Remediation
Upgrade MISP to v2.5.48 or later. If immediate upgrade is not possible, restrict attribute search and correlation functionality to trusted users, review and reapply sharing groups and publication status for events involved in correlations, and monitor access logs for unexpected reads of restricted events. Validate that correlation rows are refreshed or rebuilt after event access changes if the vendor provides a supported maintenance procedure.
Risk context
The advisory is labeled high, with CVSS v4 7.1 and CVSS v3 4.3; no EPSS score is provided. Urgency should be driven by whether the instance is internet-exposed, contains sensitive indicators, and has users with broad read access. Patch promptly for exposed or sensitive deployments, and schedule for routine patching for isolated low-sensitivity instances.
Affected products
- MISP < v2.5.48
Scores
- Severity
- high
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- 7.1
- EPSS
- —