CVE-2026-94394
📛 CVE Title
MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References
Description
When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level. The vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data. The main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- CIRCL
- CVSS severity
- MEDIUM
- CVSS score
- 6.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N- Effective score
- 6.3 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-862 - Reserved
- 2026-09-21
- Published
- 2026-09-21 13:25 UTC
- Last updated
- 2026-09-21 14:48 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94394.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-21 14:17:30 UTC
- NVD last modified
- 2026-09-21 15:17:39 UTC
NVD / KEV / EPSS data refreshed 2026-09-22 03:10 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-83912 - Assigner
- CIRCL
- Published
- Sep 21, 2026, 1:25:40 PM
- Updated
- Sep 21, 2026, 2:48:16 PM
- EUVD base score (CVSS 4.0)
-
6.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- MISP
- Products
-
MISP (0 <2.5.47)
- Aliases
-
GHSA-cj24-5f9w-vhx6
ENISA description: When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level. The vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data. The main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MISP | MISP |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Security patch patch
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/MISP/MISP/commit/f36634e57 5a6e4751-2f3f-4070-9419-94fb35b644e8
Remediations (10)
-
web:blog.qualys.com
What can I do before Microsoft releases a patch ? Qualys TruRisk™ Eliminate provides a recommended mitigation for CVE - 2026 -69414 that can be applied to affected systems while Microsoft works on a fix . Assets can then be reassessed in Qualys VMDR to verify the remediation outcome.
2026-09-22 17:07 UTC -
web:cvetodo.com
CVE-2026-94394 is a CVSS 6.3 Missing Authorization vulnerability in MISP. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-22 17:07 UTC -
web:learn.microsoft.com
In this library you will find the following security documents that have been released by the Microsoft Security Response Center (MSRC). The MSRC investigates all reports of security vulnerabilities affecting Microsoft products and services, and releases these documents as part of the ongoing effort to help you manage security risks and help keep your systems protected. Please use the ...
2026-09-22 17:07 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-09-22 17:07 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-09-22 17:07 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-22 17:07 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-22 17:07 UTC -
web:support.microsoft.com
This Hotpatch update for Windows 11, version 25H2 and 24H2 (KB5079420), improves functionality, performance, and reliability. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of ...
2026-09-22 17:07 UTC -
web:tech-insider.org
A proof-of-concept exploit published on August 12, 2026 undid Microsoft's fix for a Defender privilege-escalation bug just one day after that month's Patch Tuesday, handing attackers a working path back to SYSTEM-level access on fully patched Windows 11 25H2 and Windows Server 2025 machines. The bypass, tracked as CVE - 2026 -69414 and nicknamed ShieldBreak, targets the same Malware ...
2026-09-22 17:07 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-22 17:07 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-94394.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94394",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T14:35:25.970564Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T14:48:16.963Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"modules": [
"ObjectReferencesController"
],
"product": "MISP",
"programFiles": [
"app/Controller/ObjectReferencesController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.47",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.<br><br><p>Because of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.</p>The vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.<br><br>The main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see.<br>"
}
],
"value": "When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user.\n\nBecause of this, someone who can view an event could potentially access attributes or objects inside that event that were meant to be restricted to a specific sharing group or distribution level.\n\nThe vulnerability affects authenticated users who are not site administrators and who already have access to an event containing more restricted data.\n\nThe main impact is that users may be able to view sensitive attribute values, object details, or related object data that they should not normally be allowed to see."
}
],
"impacts": [
{
"capecId": "CAPEC-109",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-109 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T13:25:40.360Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/f36634e57"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation.</p>"
}
],
"value": "The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation."
}
],
"title": "MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "review",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact affected and fixed version numbers are not specified in the patch metadata. The tag_version_boundary indicates the fix commit is 140 commits after v2.5.47, but the precise release version containing the fix is unknown.",
"The CAPEC-109 (Parameter Tampering) mapping is the closest available match but is not a perfect fit; the vulnerability is more precisely a missing granular authorization check rather than parameter manipulation. No CAPEC specifically models broken sub-entity access control.",
"The CVSS SC:H rating assumes that the exposed attribute/object data constitutes sensitive information (e.g., IOCs, malware indicators, threat intelligence) whose unauthorized disclosure is a significant confidentiality impact. If the data is considered low-sensitivity, SC:L may be more appropriate.",
"The vulnerability requires the attacker to already have event-level access; it does not grant access to events the user cannot see. The bypass is limited to granular restrictions within an already-accessible event.",
"The patch only addresses the add() method in ObjectReferencesController; other methods or controllers with similar patterns may or may not be affected, but no evidence of additional affected code paths is present in this patch."
],
"capecRationale": [
{
"capecId": "CAPEC-109",
"rationale": "The closest plausible CAPEC is Parameter Tampering. An authenticated user supplies an objectId parameter to the add() endpoint, and the application fails to enforce proper authorization on the sub-entities (attributes, objects, object attributes) associated with that object. The user effectively 'tampers' with the scope of accessible data by leveraging event-level access to reach restricted sub-entities. This is not a perfect match because the user is not modifying a parameter to an invalid value but rather exploiting the absence of a check on a valid parameter's sub-resources. No CAPEC specifically models 'broken granular access control' or 'insecure direct object reference at sub-entity level,' making CAPEC-109 the best available approximation."
}
],
"commit": "f36634e57b93ad9daa3ab9530b76b9e5cba796e2",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
}
],
"cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: The attack requires no special conditions beyond having a valid account with event-level access; no race conditions or complex setup needed. AT:N: No manipulation of a separate attack target is required. PR:L: The attacker needs a low-privilege authenticated account (any non-site-admin user with access to an event containing restricted attributes/objects). UI:N: No victim interaction is required; the attacker simply calls the API endpoint. VC:N/VI:N/VA:N: The MISP server itself (the vulnerable component) is not compromised in its own confidentiality, integrity, or availability. SC:H: The resource impact is high because restricted attribute values, object metadata, and object-attribute data that are explicitly gated by distribution levels and sharing groups are exposed to an unauthorized user. SI:N: No integrity impact on the data. SA:N: No safety impact.",
"fixSummary": "The fix introduces granular authorization checks in the ObjectReferencesController add() method. For non-site-admin users, the query conditions for attributes, objects, and object attributes are now augmented with OR clauses that restrict results to: (1) entities belonging to the user's own event, (2) entities with unrestricted distribution levels (1, 2, 3, 5), or (3) entities with distribution level 4 whose sharing_group_id is in the user's authorized sharing group list. This ensures that only data the user is explicitly authorized to see under MISP's distribution and sharing-group model is included in the object reference operation.",
"generatedAt": "2026-09-21T13:15:28.001598Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 5
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "2688fca1334e3016b8b885ce926749f8d47e49d7b657cf38f7b2edcd6eaf6cf0",
"patchSummary": "In app/Controller/ObjectReferencesController.php, the add() method is modified to build dynamic condition arrays ($attributeConditions, $objectConditions, $objectAttributeConditions) that incorporate the current user's role and authorized sharing group IDs. For non-site-admin users, each condition array gains an OR clause filtering by event ownership, distribution levels (1,2,3,5), or distribution level 4 with a matching sharing_group_id from the user's authorized IDs. These condition arrays replace the previously hardcoded minimal conditions (deleted=0, object_id=0) in the Contain clauses for Attribute, Object, and nested Object.Attribute queries. The user's authorized sharing group IDs are obtained via SharingGroup->authorizedIds($user).",
"patchTruncated": false,
"patches": [
{
"commit": "f36634e57b93ad9daa3ab9530b76b9e5cba796e2",
"patchSha256": "2688fca1334e3016b8b885ce926749f8d47e49d7b657cf38f7b2edcd6eaf6cf0",
"source": "https://github.com/MISP/MISP/commit/f36634e57.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/f36634e57.patch",
"subject": "fix: [security] Extended event granular restrictions ignored"
}
],
"source": "https://github.com/MISP/MISP/commit/f36634e57.patch",
"subject": "fix: [security] Extended event granular restrictions ignored",
"tagVersionBoundary": {
"commits_after_fix": 140,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.47",
"version": "2.5.47",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The ObjectReferencesController add() method was missing authorization checks for granular distribution-level and sharing-group restrictions on attributes, objects, and object attributes. Only event-level access was verified, while the sub-entity level access controls (distribution levels 1-5, sharing group membership) were entirely absent from the query conditions. This is a classic missing authorization check at a finer granularity than what was enforced."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20106"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-94394",
"datePublished": "2026-09-21T13:25:40.360Z",
"dateReserved": "2026-09-21T13:25:38.483Z",
"dateUpdated": "2026-09-21T14:48:16.963Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}