CVE-2026-10863
Last modified
CVE-2026-10863 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending on how the value was processed by the underlying data access layer, this could allow manipulation of database query ordering and potentially expose the application to unsafe query construction. The patch removes order from the set of request-controlled parameters and instead sets the ordering server-side to occurrence desc after processing allowed user parameters. Affected component: app/Controller/CorrelationsController.php, overCorrelations() Security impact: An authenticated attacker could influence the ordering clause used by the over-correlations query. The direct impact appears limited to query manipulation unless further evidence confirms SQL injection or unauthorized data exposure through the manipulated ordering expression.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Misp-Project | Misp | < 2.5.39 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-10863?
How severe is CVE-2026-10863?
How do I fix CVE-2026-10863?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10856A URL validation flaw in the MISP dashboard button widget al…6.1
- CVE-2026-10857Improper neutralization of input during web page generation …6.1
- CVE-2026-1086The Font Pairing Preview For Landing Pages plugin for WordPr…4.3
- CVE-2026-10860A logic error in the MISP CRUD component delete handler allo…6.5
- CVE-2026-10861An open redirect vulnerability existed in MISP UsersControll…6.1
- CVE-2026-10862The Accordions plugin for WordPress is vulnerable to Stored …6.4
- CVE-2026-10864A vulnerability in the MISP dashboard widgets allowed an aut…4.3
- CVE-2026-10865The Cost Calculator Builder plugin for WordPress is vulnerab…5.3
- CVE-2026-10868A mass assignment vulnerability exists in the MISP user edit…9
- CVE-2026-1087The Guardian News Feed plugin for WordPress is vulnerable to…4.3
- CVE-2026-10870A flaw has been found in Shibby Tomato 1.28.0000. This affec…7.3
- CVE-2026-10871A vulnerability has been found in Shibby Tomato 1.28.0000. T…7.3
Are you affected by CVE-2026-10863?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
