CVE-2026-104914
Last modified
CVE-2026-104914 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users.
Description
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104914?
How severe is CVE-2026-104914?
How do I fix CVE-2026-104914?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104901MISP contains a cross-site scripting (XSS) vulnerability in …5.1
- CVE-2026-104906MISP contains a cross-site scripting (XSS) vulnerability in …6.2
- CVE-2026-104907MISP contains a cross-site scripting (XSS) vulnerability in …4.8
- CVE-2026-104908MISP contains an improper input validation vulnerability in …7.1
- CVE-2026-104910MISP contains an authorization bypass in the related events …5.3
- CVE-2026-104912MISP contains an authorization flaw in its correlation handl…7.1
- CVE-2026-104982A flaw has been found in Linux Mint Xreader up to 4.6.5. Thi…4.3
- CVE-2026-104983A vulnerability has been found in Linux Mint Xreader up to 4…6.3
- CVE-2026-104988A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST…8.1
- CVE-2026-104991Phproject before 1.8.7 contains a missing object-level autho…7.1
- CVE-2026-104994Trivy before 0.71.0 allows directory traversal in Terraform …2.5
- CVE-2026-1050A flaw has been found in risesoft-y9 Digital-Infrastructure …7.3
Are you affected by CVE-2026-104914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
