CVE-2026-107175: falha de média gravidade em MISP
MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes
Publicada em
10Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified.
When a user edits an existing event and changes its distribution or sharing_group_id, the internal before-save hook stored the incoming (new) data rather than the previously persisted values. As a result, the after-save comparison that determines whether a correlation refresh is needed never detected the change, and stale correlations persisted.
Security impact:
- Stale correlations may continue to expose event data to users in a broader sharing group after the event has been moved to a more restrictive group, resulting in unintended information disclosure.
- Conversely, newly relevant correlations may not appear after a distribution widening, degrading the completeness of threat intelligence sharing.
Preconditions:
- An authenticated user with write access to at least one MISP event.
- The user modifies the event's distribution or sharing_group_id field.
Affected versions: <2.5.48
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Produtos afetados
MISP · MISPCVEs relacionadas — MISP
No mesmo produto, das mais perigosas para as menos.
CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2026-95698MEDIUMMISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization NameEPSS 0.7%CVE-2026-39962HIGHLDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variableEPSS 0.7%CVE-2026-106513MEDIUMMISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration ChangeEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%