{"api_version":"1","generated_at":"2026-09-23T01:39:24+00:00","cve":"CVE-2026-94394","urls":{"html":"https://cve.report/CVE-2026-94394","api":"https://cve.report/api/cve/CVE-2026-94394.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-94394","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-94394"},"summary":{"title":"MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References","description":"When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.\n\nBecause of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.\n\nThe vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.\n\nThe main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-09-21 14:17:30","updated_at":"2026-09-21 15:17:39"},"problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/f36634e57","name":"https://github.com/MISP/MISP/commit/f36634e57","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-94394","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94394","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.47 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jeroen Pinoy","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"94394","cve":"CVE-2026-94394","epss":"0.002070000","percentile":"0.111200000","score_date":"2026-09-22","updated_at":"2026-09-23 00:06:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-94394","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-21T14:35:25.970564Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-21T14:48:16.963Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"modules":["ObjectReferencesController"],"product":"MISP","programFiles":["app/Controller/ObjectReferencesController.php"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.47","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.<br><br><p>Because of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.</p>The vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.<br><br>The main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.<br>"}],"value":"When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.\n\nBecause of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.\n\nThe vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.\n\nThe main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see."}],"impacts":[{"capecId":"CAPEC-109","descriptions":[{"lang":"en","value":"CAPEC-109 Parameter Tampering"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-21T13:25:40.360Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/f36634e57"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation.</p>"}],"value":"The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation."}],"title":"MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"review","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The exact affected and fixed version numbers are not specified in the patch metadata. The tag_version_boundary indicates the fix commit is 140 commits after v2.5.47, but the precise release version containing the fix is unknown.","The CAPEC-109 (Parameter Tampering) mapping is the closest available match but is not a perfect fit; the vulnerability is more precisely a missing granular authorization check rather than parameter manipulation. No CAPEC specifically models broken sub-entity access control.","The CVSS SC:H rating assumes that the exposed attribute/object data constitutes sensitive information (e.g., IOCs, malware indicators, threat intelligence) whose unauthorized disclosure is a significant confidentiality impact. If the data is considered low-sensitivity, SC:L may be more appropriate.","The vulnerability requires the attacker to already have event-level access; it does not grant access to events the user cannot see. The bypass is limited to granular restrictions within an already-accessible event.","The patch only addresses the add() method in ObjectReferencesController; other methods or controllers with similar patterns may or may not be affected, but no evidence of additional affected code paths is present in this patch."],"capecRationale":[{"capecId":"CAPEC-109","rationale":"The closest plausible CAPEC is Parameter Tampering. An authenticated user supplies an objectId parameter to the add() endpoint, and the application fails to enforce proper authorization on the sub-entities (attributes, objects, object attributes) associated with that object. The user effectively 'tampers' with the scope of accessible data by leveraging event-level access to reach restricted sub-entities. This is not a perfect match because the user is not modifying a parameter to an invalid value but rather exploiting the absence of a check on a valid parameter's sub-resources. No CAPEC specifically models 'broken granular access control' or 'insecure direct object reference at sub-entity level,' making CAPEC-109 the best available approximation."}],"commit":"f36634e57b93ad9daa3ab9530b76b9e5cba796e2","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"}],"cvssRationale":"AV:N: MISP is a network-accessible web application. AC:L: The attack requires no special conditions beyond having a valid account with event-level access; no race conditions or complex setup needed. AT:N: No manipulation of a separate attack target is required. PR:L: The attacker needs a low-privilege authenticated account (any non-site-admin user with access to an event containing restricted attributes/objects). UI:N: No victim interaction is required; the attacker simply calls the API endpoint. VC:N/VI:N/VA:N: The MISP server itself (the vulnerable component) is not compromised in its own confidentiality, integrity, or availability. SC:H: The resource impact is high because restricted attribute values, object metadata, and object-attribute data that are explicitly gated by distribution levels and sharing groups are exposed to an unauthorized user. SI:N: No integrity impact on the data. SA:N: No safety impact.","fixSummary":"The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation.","generatedAt":"2026-09-21T13:15:28.001598Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":9,"assumptionCount":5,"confidence":"medium","model":"qwen3.8:27b","score":5}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"2688fca1334e3016b8b885ce926749f8d47e49d7b657cf38f7b2edcd6eaf6cf0","patchSummary":"In app/Controller/ObjectReferencesController.php, the add() method is modified to build dynamic condition arrays ($attributeConditions, $objectConditions, $objectAttributeConditions) that incorporate the current user's role and authorized sharing group IDs. For non-site-admin users, each condition array gains an OR clause filtering by event ownership, distribution levels (1,2,3,5), or distribution level 4 with a matching sharing_group_id from the user's authorized IDs. These condition arrays replace the previously hardcoded minimal conditions (deleted=0, object_id=0) in the Contain clauses for Attribute, Object, and nested Object.Attribute queries. The user's authorized sharing group IDs are obtained via SharingGroup->authorizedIds($user).","patchTruncated":false,"patches":[{"commit":"f36634e57b93ad9daa3ab9530b76b9e5cba796e2","patchSha256":"2688fca1334e3016b8b885ce926749f8d47e49d7b657cf38f7b2edcd6eaf6cf0","source":"https://github.com/MISP/MISP/commit/f36634e57.patch","sourceUrl":"https://github.com/MISP/MISP/commit/f36634e57.patch","subject":"fix: [security] Extended event granular restrictions ignored"}],"source":"https://github.com/MISP/MISP/commit/f36634e57.patch","subject":"fix: [security] Extended event granular restrictions ignored","tagVersionBoundary":{"commits_after_fix":140,"repository":"https://github.com/MISP/MISP","tag":"v2.5.47","version":"2.5.47","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-862","rationale":"The ObjectReferencesController add() method was missing authorization checks for granular distribution-level and sharing-group restrictions on attributes, objects, and object attributes. Only event-level access was verified, while the sub-entity level access controls (distribution levels 1-5, sharing group membership) were entirely absent from the query conditions. This is a classic missing authorization check at a finer granularity than what was enforced."}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20106"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-94394","datePublished":"2026-09-21T13:25:40.360Z","dateReserved":"2026-09-21T13:25:38.483Z","dateUpdated":"2026-09-21T14:48:16.963Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-21 14:17:30","lastModifiedDate":"2026-09-21 15:17:39","problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-21T14:35:25.970564Z","id":"CVE-2026-94394","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"94394","Ordinal":"1","Title":"MISP ObjectReferencesController: Granular Distribution and Shari","CVE":"CVE-2026-94394","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"94394","Ordinal":"1","NoteData":"When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.\n\nBecause of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.\n\nThe vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.\n\nThe main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.","Type":"Description","Title":"MISP ObjectReferencesController: Granular Distribution and Shari"}]}}}