MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes.

As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data.

A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate.

Preconditions:

- An authenticated user with access to a community-distributed event

- The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution

Impact:

- Unauthorized disclosure of attributes belonging to restricted objects

- Potential exposure of organisation-specific threat intelligence to other organisations

Affected versions: <2.5.48

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48
Title MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CWE-862
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-01T15:24:42.585Z

Reserved: 2026-10-01T08:33:03.219Z

Link: CVE-2026-103659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:08.213

Modified: 2026-10-01T16:17:37.713

Link: CVE-2026-103659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:15:05Z

Weaknesses