Improper Access Control in MISP Attribute Search and View Endpoints
CVE-2026-104914

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104914?

MISP has a vulnerability that allows authenticated users to access soft-deleted attributes from events owned by other organizations, undermining the intended confidentiality of sensitive threat intelligence. This issue arises when users issue queries for deleted attributes through the attribute search or paginated view endpoints, failing to restrict visibility based on ownership. Although event detail views are secured, the search functionalities lack proper access control, potentially disclosing sensitive information that should remain restricted.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iglocska
Claude Opus 5.5 (1M context)
elhoim
.