Misp · Misp · CVE-2026-104910
**Name of the Vulnerable Software and Affected Versions**
MISP versions prior to commit 2ffa97f05
**Description**
An authorization bypass exists in the related events listing functionality. When a user requests a list of events correlated to a specific event, the system retrieves metadata directly from the correlation table without re-validating the caller's access rights for each related event. Because the correlation table uses a snapshot of the distribution level and sharing group from the time of creation and lacks a published flag, metadata such as titles, dates, and correlating value counts may be disclosed for events that are unpublished or have updated access restrictions. This allows an authenticated user with access to at least one event to perform reconnaissance on threat-intelligence event names and timelines across different sharing groups.
**Recommendations**
Update to the version containing commit 2ffa97f05.