CVE Vulnerabilities

CVE-2026-104910

Improper Authorization

Published: Oct 02, 2026 | Modified: Oct 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the callers access rights against each related event.

The correlation table stores a snapshot of the events distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts).

Preconditions:

  • An authenticated user with access to at least one event in MISP.

  • The existence of correlation entries linking that event to other events the user should not be able to view.

Impact:

  • Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.

  • Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.

Affected: MISP versions prior to the fix commit (2ffa97f05).

Weakness

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Potential Mitigations

  • Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) to enforce the roles at the appropriate boundaries.
  • Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
  • For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
  • One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.

References