Executive brief
MISP is an open-source platform used for sharing threat intelligence and indicators of compromise across organizations. The OnDemand correlation engine improperly disclosed restricted events and attributes to authenticated users by returning correlation results without checking access control restrictions. An attacker with a low-privilege account could learn about sensitive threat intelligence they were not authorized to access.
Technical details
The vulnerability is an authorization bypass in MISP's OnDemand correlation engine. The correlation collection logic matched attributes solely on attribute values without evaluating distribution, sharing group, organization, or other access-control restrictions. Additionally, cached correlation data was not re-validated against current access control lists before being returned. An authenticated user could exploit this by creating or querying attributes that correlate with restricted events, potentially accessing sensitive intelligence. The patch enforces access control by filtering correlations through the existing fetchAttributesSimple() authorization logic and re-validating cached results against current ACLs.
Affected products
- MISP MISP prior to 2.5 (commit f51342f30)
Timeline
- 2026-09-03: disclosed: CVE-2026-85226 published
- 2026-08-19: patched: Security patch committed (f51342f30)