Authorization Flaw in MISP Affecting Correlation Engine
CVE-2026-85226

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85226?

The MISP platform has a significant authorization flaw in its OnDemand correlation engine, which compromises access controls. When correlating attributes, the engine only used matching values without considering user permissions related to sharing groups, organizations, or distribution. This oversight allowed authenticated users, even with low privileges, to retrieve correlation results that contained sensitive attributes or events outside their authorized access. The vulnerability also impacted previously cached correlation data, potentially exposing outdated access control information. The implemented patch rectifies this by incorporating user-specific checks, ensuring filtered results and adherence to current access control lists (ACLs) for all correlated data.

Affected Version(s)

misp 0 <= 2.5.45

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andras Iklody
elhoim (David André)
Claude Opus 5 (1M context)
.