天下漏洞,尽知其名
MEDIUM

CVE-2026-104910 MISP 授权绕过漏洞

影响攻击者可越权获取未授权事件的元数据

MEDIUM
暂无 CVSS 评分
AI 研判

MISP 的相关事件列表功能存在授权绕过漏洞。系统在返回与指定事件关联的事件列表时,直接从关联表读取元数据,未重新校验调用者对每个关联事件的访问权限。关联表保存的是关联创建时的分发级别与共享组快照,且不含发布标志,导致未发布或分发级别、共享组已变更的事件仍被返回。

影响范围

MISP

漏洞详情

漏洞类型为授权绕过(访问控制缺陷)。成因是相关事件列表接口信任关联表中的历史快照数据,未按当前权限逐条重新校验。利用方式是已认证用户请求某事件的相关事件列表,即可获得本无权查看事件的标题、日期及关联值计数等元数据。

利用条件与风险

利用前提是攻击者拥有 MISP 有效账户且至少可访问一个事件,且存在指向无权查看事件的关联记录。实战中可导致威胁情报事件名称与时间线的越权泄露,属于信息泄露与侦察风险。

修复建议

官方修复方案暂无公开信息,建议关注 MISP 官方安全公告并升级至修复版本;临时缓解措施包括限制普通用户的相关事件查询权限、审查共享组与分发配置,并监控异常的相关事件列表请求。

原始情报

MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller’s access rights against each related event.

The correlation table stores a snapshot of the event’s distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts).

Preconditions:

– An authenticated user with access to at least one event in MISP.

– The existence of correlation entries linking that event to other events the user should not be able to view.

Impact:

– Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.

– Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.

Affected: MISP versions prior to the fix commit (2ffa97f05).