Executive brief
MISP is an open-source threat intelligence platform used to share and manage security indicators. A flaw in its freetext feed preview feature bypassed access controls and allowed users to see restricted event data and feed metadata they should not have access to. This could expose sensitive threat intelligence and organizational security information to unauthorized users.
Technical details
The vulnerability is an authorization bypass in the freetext feed preview functionality of MISP. The preview performed attribute correlation lookups and cross-feed lookups without applying the requesting user's ACL (access control list), role-based restrictions, sharing group settings, or object-level permissions. The vulnerable code scoped queries only by attribute values and deletion status, bypassing MISP's multi-level access control model (event, organization, sharing-group, attribute, and object level). Additionally, feed URLs configured for internal use only were exposed in correlation results, and feeds marked as not lookup_visible were included in results. The fix applies proper ACL filtering to correlation searches, removes sensitive feed URLs from responses, restricts feed visibility according to permissions, and corrects type-comparison logic in authorization checks.
Affected products
- MISP Project MISP ≤2.5.45
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixes available in commits 1fb6220 and 4b69160