MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.
When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.
Preconditions:
An authenticated MISP user with at least read access to an event owned by another organization.
The user issues a query for deleted attributes (search or paginated view with the deleted filter).
Impact:
Affected versions: MISP versions prior to v2.5.48.
{
"cna_assigner": "CIRCL",
"cwe_ids": [
"CWE-284",
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104914.json"
}