{"api_version":"1","generated_at":"2026-10-02T22:00:09+00:00","cve":"CVE-2026-104912","urls":{"html":"https://cve.report/CVE-2026-104912","api":"https://cve.report/api/cve/CVE-2026-104912.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-104912","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-104912"},"summary":{"title":"MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data","description":"MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48.","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-10-02 16:16:49","updated_at":"2026-10-02 16:16:49"},"problem_types":["CWE-284","CWE-862","CWE-862 CWE-862 Missing Authorization","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"7.1","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/100235bd9","name":"https://github.com/MISP/MISP/commit/100235bd9","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-104912","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104912","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.48 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 5.5 (1M context)","lang":"en"},{"source":"CNA","value":"elhoim","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"modules":["app/Model/Behavior/DefaultCorrelationBehavior.php"],"product":"MISP","repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"},{"lang":"en","type":"reporter","value":"elhoim"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.</p><p>Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.</p><p>Preconditions:</p><p>- An authenticated user with at least read access to some events in the instance.</p><p>- The existence of correlations between events, at least one of which has been restricted after the correlation was created.</p><p>Impact:</p><p>- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.</p><p>Affected versions: MISP prior to v2.5.48.</p>"}],"value":"MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48."}],"impacts":[{"capecId":"CAPEC-114","descriptions":[{"lang":"en","value":"CAPEC-114 Exploiting Incorrectly Adjusted Privileges"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T16:02:40Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-02T16:04:50.580Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/100235bd9"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.</p>"}],"value":"The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage."}],"title":"MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 38 commits after fix); the exact first affected version is not stated in the patch.","CVSS PR:L assumes the attacker needs a standard authenticated MISP account with read access to at least one event; no evidence supports a lower or higher privilege requirement.","CAPEC-114 is the closest available pattern; the actual mechanism is a stale authorization snapshot rather than a classic privilege-escalation vector, so the mapping is approximate.","The patch does not specify whether the vulnerability requires the event to have been restricted after correlation creation, or whether other state changes (e.g., sharing group modification) also trigger the issue; the commit message mentions 'restricted' as the primary scenario.","No public exploit or PoC is referenced; exploitation status is assumed to be 'none'."],"capecRationale":[{"capecId":"CAPEC-114","rationale":"The authorization state used for correlation lookups was incorrectly adjusted (stale) relative to the actual event ACL. An attacker with a legitimate account could exploit this misalignment to access data beyond their intended privilege scope. This is the closest CAPEC pattern; the exact mechanism is a stale authorization snapshot rather than a classic privilege-escalation primitive, so the mapping is approximate."}],"commit":"100235bd99b9f57a5a09976412d54e2001d2e0c4","confidence":"medium","credits":[{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5.5 (1M context)"},{"lang":"en","type":"reporter","value":"elhoim"}],"cvssRationale":"Network vector: MISP is a web application accessible over the network. Low complexity: the attacker simply performs a normal attribute search that triggers correlations; no race condition or special setup is needed. No attack requirements: the stale correlation row exists naturally after any event restriction. Low privileges: the attacker needs an authenticated account with read access to at least one event. No user interaction: the attacker initiates the search themselves. High vulnerability-component confidentiality impact: full attribute values and event metadata of restricted events are exposed. No integrity or availability impact on the vulnerable or subsequent components.","fixSummary":"The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.","generatedAt":"2026-10-02T16:02:40.166976Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":5,"confidence":"medium","model":"qwen3.8:27b","score":7}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d","patchSummary":"In DefaultCorrelationBehavior.php: (1) runGetRelatedAttributes now builds query conditions that include the live attribute ACL (buildConditions) for non-site-admin users, and ensures Event and Object are contained in the query for proper filtering; (2) after fetching related attributes, Event and Object sub-objects are unset from each result; (3) fetchRelatedEventIds now passes its results through a new __filterVisibleEventIds method that queries the Event model with createEventConditions to verify each event ID is still visible to the user; (4) the new __filterVisibleEventIds method returns the event IDs unchanged for site admins or empty lists, otherwise filters against the live event ACL.","patchTruncated":false,"patches":[{"commit":"100235bd99b9f57a5a09976412d54e2001d2e0c4","date":"Thu, 24 Sep 2026 12:12:56 +0200","patchSha256":"a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d","source":"https://github.com/MISP/MISP/commit/100235bd9.patch","sourceUrl":"https://github.com/MISP/MISP/commit/100235bd9.patch","subject":"fix: [security] Check correlations against the live event ACL"}],"source":"https://github.com/MISP/MISP/commit/100235bd9.patch","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-02T16:02:40Z","version":"2.0.3"},"subject":"fix: [security] Check correlations against the live event ACL","tagVersionBoundary":{"commits_after_fix":38,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-862","rationale":"The correlation lookup path failed to enforce the current (live) authorization state of the target events and attributes. Access was granted based on a stale snapshot rather than the actual ACL, effectively missing the authorization check for restricted events."},{"cweId":"CWE-284","rationale":"The access control decision relied on outdated data (the distribution columns copied onto the correlation row) that did not reflect the current published/sharing-group state of the event, leading to improper access control."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (100235bd99b9f57a5a09976412d54e2001d2e0c4): fix: [security] Check correlations against the live event ACL","id":"evt-fix-developed-1","references":["https://github.com/MISP/MISP/commit/100235bd9.patch"],"timestamp":"2026-09-24T10:12:56Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20312"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-104912","datePublished":"2026-10-02T16:04:50.580Z","dateReserved":"2026-10-02T16:04:47.753Z","dateUpdated":"2026-10-02T16:04:50.580Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-02 16:16:49","lastModifiedDate":"2026-10-02 16:16:49","problem_types":["CWE-284","CWE-862","CWE-862 CWE-862 Missing Authorization","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","ssvcData":{"timestamp":"2026-10-02T16:02:40Z","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"Supplier","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"104912","Ordinal":"1","Title":"MISP Correlation Authorization Bypass Exposes Restricted Event a","CVE":"CVE-2026-104912","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"104912","Ordinal":"1","NoteData":"MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48.","Type":"Description","Title":"MISP Correlation Authorization Bypass Exposes Restricted Event a"}]}}}