Authorization Flaw in MISP Affecting Correlation Engine
CVE-2026-85226
What is CVE-2026-85226?
The MISP platform has a significant authorization flaw in its OnDemand correlation engine, which compromises access controls. When correlating attributes, the engine only used matching values without considering user permissions related to sharing groups, organizations, or distribution. This oversight allowed authenticated users, even with low privileges, to retrieve correlation results that contained sensitive attributes or events outside their authorized access. The vulnerability also impacted previously cached correlation data, potentially exposing outdated access control information. The implemented patch rectifies this by incorporating user-specific checks, ensuring filtered results and adherence to current access control lists (ACLs) for all correlated data.
Affected Version(s)
misp 0 <= 2.5.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
