PT-2026-85057 · Misp · Misp
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
An authorization flaw exists in the OnDemand correlation engine where correlations are calculated based only on matching attribute values, ignoring distribution, sharing group, organization, and other access-control restrictions. This allows an authenticated low-privileged user to receive correlation results for attributes or events they are not authorized to access by querying or creating attributes that correlate with restricted content. The issue stems from the correlation collection path failing to account for the requesting user and the use of potentially stale denormalized access-control information in paths relying on stored correlation data. The system utilizes the
fetchAttributesSimple() function to evaluate restrictions against live data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp