PT-2026-85057 · Misp · Misp

·

CVE-2026-85226

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description An authorization flaw exists in the OnDemand correlation engine where correlations are calculated based only on matching attribute values, ignoring distribution, sharing group, organization, and other access-control restrictions. This allows an authenticated low-privileged user to receive correlation results for attributes or events they are not authorized to access by querying or creating attributes that correlate with restricted content. The issue stems from the correlation collection path failing to account for the requesting user and the use of potentially stale denormalized access-control information in paths relying on stored correlation data. The system utilizes the fetchAttributesSimple() function to evaluate restrictions against live data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85226

Affected Products

Misp