Improper Access Control in MISP Attribute Search and View Endpoints
CVE-2026-104914
5.3MEDIUM
What is CVE-2026-104914?
MISP has a vulnerability that allows authenticated users to access soft-deleted attributes from events owned by other organizations, undermining the intended confidentiality of sensitive threat intelligence. This issue arises when users issue queries for deleted attributes through the attribute search or paginated view endpoints, failing to restrict visibility based on ownership. Although event detail views are secured, the search functionalities lack proper access control, potentially disclosing sensitive information that should remain restricted.
Affected Version(s)
MISP 0 < 2.5.48
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
iglocska
Claude Opus 5.5 (1M context)
elhoim
