CVE-2026-103659
Last modified
CVE-2026-103659 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes.
Description
MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103659?
How severe is CVE-2026-103659?
How do I fix CVE-2026-103659?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103592simple-php-router through 5.4.1.7 contains an IP restriction…6.5
- CVE-2026-1036The Photo Gallery by 10Web – Mobile-Friendly Image Gallery p…5.3
- CVE-2026-103641A flaw was found in GEGL. The Radiance HDR loader reads past…5.5
- CVE-2026-103651MISP contains a vulnerability in its one-time password (OTP)…7.6
- CVE-2026-103655MISP contains a vulnerability in its two-factor authenticati…9.3
- CVE-2026-103656Rejected reason: this is rejected
- CVE-2026-103662MISP contains a reflected cross-site scripting (XSS) vulnera…5.1
- CVE-2026-103664MISP contains a reflected cross-site scripting (XSS) vulnera…4.8
- CVE-2026-103678A flaw was found in tnef. An attacker can exploit this vulne…5.4
- CVE-2026-103679A flaw was found in tnef. A remote attacker could exploit th…6.5
- CVE-2026-103680A flaw was found in tnef. A heap-based buffer overflow can o…3.1
- CVE-2026-103686A flaw has been found in rhukster dom-sanitizer up to 1.0.15…3.5
Are you affected by CVE-2026-103659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
