CVE-2026-104912EPSS p9.8%
CVE-2026-104912CVE-2026-104912
Description
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.
Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.
Preconditions:
- An authenticated user with at least read access to some events in the instance.
- The existence of correlations between events, at least one of which has been restricted after the correlation was created.
Impact:
- Confidentiality: exp
Scoring
| EPSS | 0.21% probability of exploitation · percentile 9.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-03 |