Common Weakness Enumeration

CWE-862

Allowed-with-Review

Missing Authorization

Abstraction: Class · Status: Incomplete

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

17384 vulnerabilities reference this CWE, most recent first.

CVE-2026-104991 (GCVE-0-2026-104991)

Vulnerability from cvelistv5 – Published: 2026-10-02 19:33 – Updated: 2026-10-02 19:33 X_Open Source
VLAI
Title
Phproject < 1.8.7 Missing Authorization via Issues REST API
Summary
Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents and comments, including owner and author email addresses, and post unauthorized comments to issues they should not have access to.
CWE
References
Impacted products
Vendor Product Version
Alanaktion phproject Affected: 1.1.6 , < 1.8.7 (semver)
    cpe:2.3:a:alanaktion:phproject:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-10-02 00:00
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/Alanaktion/phproject",
          "product": "phproject",
          "repo": "https://github.com/Alanaktion/phproject",
          "vendor": "Alanaktion",
          "versions": [
            {
              "lessThan": "1.8.7",
              "status": "affected",
              "version": "1.1.6",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:alanaktion:phproject:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "1.8.7",
                  "versionStartIncluding": "1.1.6",
                  "vulnerable": true
                }
              ],
              "operator": "OR"
            }
          ],
          "operator": "OR"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Alisher Qarshibayev"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulnCheck"
        }
      ],
      "datePublic": "2026-10-02T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents and comments, including owner and author email addresses, and post unauthorized comments to issues they should not have access to."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T19:33:47.741Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Advisory",
          "tags": [
            "vendor-advisory",
            "technical-description"
          ],
          "url": "https://github.com/Alanaktion/phproject/security/advisories/GHSA-mpq9-v47x-3hw8"
        },
        {
          "name": "Vendor Patch",
          "tags": [
            "vendor-advisory",
            "issue-tracking"
          ],
          "url": "https://github.com/Alanaktion/phproject/releases/tag/v1.8.7"
        },
        {
          "name": "VulnCheck Advisory",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/phproject-missing-authorization-via-issues-rest-api"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "tags": [
        "x_open-source"
      ],
      "title": "Phproject \u003c 1.8.7 Missing Authorization via Issues REST API",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-104991",
    "datePublished": "2026-10-02T19:33:47.741Z",
    "dateReserved": "2026-10-02T19:29:10.044Z",
    "dateUpdated": "2026-10-02T19:33:47.741Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104914 (GCVE-0-2026-104914)

Vulnerability from cvelistv5 – Published: 2026-10-02 16:09 – Updated: 2026-10-02 16:09
VLAI
Title
MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View
Summary
MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
Supplier · CIRCL (v2.0.3)
Decision recorded 2026-10-02 16:06 UTC
CWE
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.48 (semver)
    cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Create a notification for this product.
GCVE extensions
AI involvement GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
Patch provenance GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-10-02 16:06
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/bd81c23cf.patch 9673ee1d4db2…
Confidence
medium
Commit Subject Patch SHA-256
bd81c23cf2ac fix: [security] Show soft-deleted attributes only to the 9673ee1d4db2…
Fix summary

The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user's organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.

Patch summary

Two code paths were modified:1. Event.php (fetchPaginatedAttributes): When the deleted filter is active and the user lacks perm_sync, an additional subquery condition is appended requiring the event owner's org_id to match the user's org_id. The original blanket deleted=0 or deleted=1 condition is replaced with an OR/AND structure that permits non-deleted attributes for all users but restricts deleted attributes to the owning org.2. MispAttribute.php (fetchAttributes): In the deleted='only' branch, when the user lacks perm_sync, an additional AND condition Event.org_id = user.org_id is added to the query conditions, scoping results to the user's own organization.

CVSS rationale

AV:N: The vulnerability is exploitable over the network via the MISP web API. AC:L: Exploitation requires only a standard query with the deleted-attribute filter; no race conditions or complex setup. AT:N: No special attack requirements. PR:L: An authenticated user with at least read access to an event owned by another organization is required. UI:N: No victim interaction needed; the data is returned in the API response. VC:L: Confidentiality impact is limited to soft-deleted attributes (a subset of event data) from other organizations; not all data is exposed. VI:N, VA:N: No integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N: No impact on subsequent components.

Weakness rationale
  • CWE-862 The attribute search and paginated view code paths were missing the authorization check that restricts soft-deleted attribute visibility to the owning organization. The event view had this check, but the attribute-level query paths did not, allowing any user with event visibility to retrieve soft-deleted attributes from other organizations.
  • CWE-284 More broadly, the application failed to enforce proper access control boundaries between organizations when serving soft-deleted attribute data through specific query endpoints, resulting in cross-organizational information disclosure.
Attack pattern rationale
  • CAPEC-126 This CAPEC describes leveraging legitimate application code paths to access or manipulate data beyond intended permissions. The attacker uses the legitimate attribute search and paginated view endpoints (executable code paths) to retrieve soft-deleted attributes from other organizations. The mapping is imperfect because CAPEC-126 emphasizes data alteration, whereas this vulnerability is purely an information disclosure. However, among available CAPEC patterns, this is the closest match for exploiting a legitimate code path to bypass intended access restrictions. No CAPEC specifically covers 'information disclosure via missing authorization in a query endpoint' with greater precision.
Assumptions to verify
  • The exact fixed version is not specified in the patch metadata; the fix commit is 37 commits after the v2.5.48 tag, so the fixed release is post-2.5.48 but the exact version number is unknown.
  • PR:L assumes the attacker needs at least read access to an event owned by another organization; if MISP deployments restrict cross-org event visibility more tightly, the effective privilege requirement may be higher.
  • CAPEC-126 is the closest available mapping but is not a perfect fit; the vulnerability is an information disclosure via missing authorization rather than data alteration.
  • VC:L assumes the exposure is limited to soft-deleted attributes (a subset of event data) and does not include active attributes or full event metadata.
  • The patch does not specify whether this affects all MISP deployments or only multi-organization configurations; the CVSS assumes a multi-org deployment where cross-org visibility is possible.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 7 11 medium 5
bcp-05-x-03
{
  "x_timeline": {
    "events": [
      {
        "description": "Corrective change authored (bd81c23cf2aced3c72766369dc813612edd52509): fix: [security] Show soft-deleted attributes only to the",
        "id": "evt-fix-developed-1",
        "references": [
          "https://github.com/MISP/MISP/commit/bd81c23cf.patch"
        ],
        "timestamp": "2026-09-24T11:57:21Z",
        "type": "fix-developed"
      }
    ]
  }
}
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "app/Model/Event.php",
            "app/Model/MispAttribute.php"
          ],
          "product": "MISP",
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.48",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 5.5 (1M context)"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "elhoim"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.\u003c/p\u003e\u003cp\u003eWhen a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated MISP user with at least read access to an event owned by another organization.\u003c/p\u003e\u003cp\u003e- The user issues a query for deleted attributes (search or paginated view with the deleted filter).\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility.\u003c/p\u003e\u003cp\u003eAffected versions: MISP versions prior to v2.5.48.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.\n\nWhen a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction.\n\nPreconditions:\n\n- An authenticated MISP user with at least read access to an event owned by another organization.\n\n- The user issues a query for deleted attributes (search or paginated view with the deleted filter).\n\nImpact:\n\n- Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility.\n\nAffected versions: MISP versions prior to v2.5.48."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-126",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-126 Leverage Executable Code to Alter Data"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "SSVC",
          "other": {
            "content": {
              "options": [
                {
                  "Exploitation": "none"
                },
                {
                  "Automatable": "yes"
                },
                {
                  "Technical Impact": "partial"
                }
              ],
              "role": "Supplier",
              "timestamp": "2026-10-02T16:06:38Z",
              "version": "2.0.3"
            },
            "type": "SSVC"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862 Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-284",
              "description": "CWE-284 Improper Access Control",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T16:09:40.333Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/bd81c23cf"
        },
        {
          "url": "https://github.com/elhoim"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.\u003c/p\u003e"
            }
          ],
          "value": "The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic."
        }
      ],
      "title": "MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The exact fixed version is not specified in the patch metadata; the fix commit is 37 commits after the v2.5.48 tag, so the fixed release is post-2.5.48 but the exact version number is unknown.",
                  "PR:L assumes the attacker needs at least read access to an event owned by another organization; if MISP deployments restrict cross-org event visibility more tightly, the effective privilege requirement may be higher.",
                  "CAPEC-126 is the closest available mapping but is not a perfect fit; the vulnerability is an information disclosure via missing authorization rather than data alteration.",
                  "VC:L assumes the exposure is limited to soft-deleted attributes (a subset of event data) and does not include active attributes or full event metadata.",
                  "The patch does not specify whether this affects all MISP deployments or only multi-organization configurations; the CVSS assumes a multi-org deployment where cross-org visibility is possible."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-126",
                    "rationale": "This CAPEC describes leveraging legitimate application code paths to access or manipulate data beyond intended permissions. The attacker uses the legitimate attribute search and paginated view endpoints (executable code paths) to retrieve soft-deleted attributes from other organizations. The mapping is imperfect because CAPEC-126 emphasizes data alteration, whereas this vulnerability is purely an information disclosure. However, among available CAPEC patterns, this is the closest match for exploiting a legitimate code path to bypass intended access restrictions. No CAPEC specifically covers \u0027information disclosure via missing authorization in a query endpoint\u0027 with greater precision."
                  }
                ],
                "commit": "bd81c23cf2aced3c72766369dc813612edd52509",
                "confidence": "medium",
                "credits": [
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 5.5 (1M context)"
                  },
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "elhoim"
                  }
                ],
                "cvssRationale": "AV:N: The vulnerability is exploitable over the network via the MISP web API. AC:L: Exploitation requires only a standard query with the deleted-attribute filter; no race conditions or complex setup. AT:N: No special attack requirements. PR:L: An authenticated user with at least read access to an event owned by another organization is required. UI:N: No victim interaction needed; the data is returned in the API response. VC:L: Confidentiality impact is limited to soft-deleted attributes (a subset of event data) from other organizations; not all data is exposed. VI:N, VA:N: No integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N: No impact on subsequent components.",
                "fixSummary": "The fix enforces organizational ownership checks on soft-deleted attribute queries. When a user without sync permission requests deleted attributes, the query is now constrained to only return soft-deleted attributes whose parent event belongs to the requesting user\u0027s organization. This aligns the attribute search and paginated view behavior with the existing event view authorization logic.",
                "generatedAt": "2026-10-02T16:06:38.209479Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 11,
                      "assumptionCount": 5,
                      "confidence": "medium",
                      "model": "qwen3.8:27b",
                      "score": 7
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "9673ee1d4db26b032b6e3a2632315d5353cd2718c9b809a5296d28a0002a3722",
                "patchSummary": "Two code paths were modified:1. Event.php (fetchPaginatedAttributes): When the deleted filter is active and the user lacks perm_sync, an additional subquery condition is appended requiring the event owner\u0027s org_id to match the user\u0027s org_id. The original blanket deleted=0 or deleted=1 condition is replaced with an OR/AND structure that permits non-deleted attributes for all users but restricts deleted attributes to the owning org.2. MispAttribute.php (fetchAttributes): In the deleted=\u0027only\u0027 branch, when the user lacks perm_sync, an additional AND condition Event.org_id = user.org_id is added to the query conditions, scoping results to the user\u0027s own organization.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "bd81c23cf2aced3c72766369dc813612edd52509",
                    "date": "Thu, 24 Sep 2026 13:57:21 +0200",
                    "patchSha256": "9673ee1d4db26b032b6e3a2632315d5353cd2718c9b809a5296d28a0002a3722",
                    "source": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
                    "subject": "fix: [security] Show soft-deleted attributes only to the"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/bd81c23cf.patch",
                "ssvc": {
                  "options": [
                    {
                      "Exploitation": "none"
                    },
                    {
                      "Automatable": "yes"
                    },
                    {
                      "Technical Impact": "partial"
                    }
                  ],
                  "role": "Supplier",
                  "timestamp": "2026-10-02T16:06:38Z",
                  "version": "2.0.3"
                },
                "subject": "fix: [security] Show soft-deleted attributes only to the",
                "tagVersionBoundary": {
                  "commits_after_fix": 37,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.48",
                  "version": "2.5.48",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-862",
                    "rationale": "The attribute search and paginated view code paths were missing the authorization check that restricts soft-deleted attribute visibility to the owning organization. The event view had this check, but the attribute-level query paths did not, allowing any user with event visibility to retrieve soft-deleted attributes from other organizations."
                  },
                  {
                    "cweId": "CWE-284",
                    "rationale": "More broadly, the application failed to enforce proper access control boundaries between organizations when serving soft-deleted attribute data through specific query endpoints, resulting in cross-organizational information disclosure."
                  }
                ]
              }
            },
            "bcp-05-x-03": {
              "x_timeline": {
                "events": [
                  {
                    "description": "Corrective change authored (bd81c23cf2aced3c72766369dc813612edd52509): fix: [security] Show soft-deleted attributes only to the",
                    "id": "evt-fix-developed-1",
                    "references": [
                      "https://github.com/MISP/MISP/commit/bd81c23cf.patch"
                    ],
                    "timestamp": "2026-09-24T11:57:21Z",
                    "type": "fix-developed"
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20248"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-104914",
    "datePublished": "2026-10-02T16:09:40.333Z",
    "dateReserved": "2026-10-02T16:09:36.435Z",
    "dateUpdated": "2026-10-02T16:09:40.333Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104912 (GCVE-0-2026-104912)

Vulnerability from cvelistv5 – Published: 2026-10-02 16:04 – Updated: 2026-10-03 15:52
VLAI
Title
MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
Summary
MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list. Because the correlation row's distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view. Preconditions: - An authenticated user with at least read access to some events in the instance. - The existence of correlations between events, at least one of which has been restricted after the correlation was created. Impact: - Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access. Affected versions: MISP prior to v2.5.48.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
Supplier · CIRCL (v2.0.3)
Decision recorded 2026-10-02 16:02 UTC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:48 UTC
CWE
References
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.48 (semver)
    cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Create a notification for this product.
GCVE extensions
AI involvement GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
Patch provenance GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-10-02 16:02
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/100235bd9.patch a38b683420d9…
Confidence
medium
Commit Subject Patch SHA-256
100235bd99b9 fix: [security] Check correlations against the live event ACL a38b683420d9…
Fix summary

The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.

Patch summary

In DefaultCorrelationBehavior.php: (1) runGetRelatedAttributes now builds query conditions that include the live attribute ACL (buildConditions) for non-site-admin users, and ensures Event and Object are contained in the query for proper filtering; (2) after fetching related attributes, Event and Object sub-objects are unset from each result; (3) fetchRelatedEventIds now passes its results through a new __filterVisibleEventIds method that queries the Event model with createEventConditions to verify each event ID is still visible to the user; (4) the new __filterVisibleEventIds method returns the event IDs unchanged for site admins or empty lists, otherwise filters against the live event ACL.

CVSS rationale

Network vector: MISP is a web application accessible over the network. Low complexity: the attacker simply performs a normal attribute search that triggers correlations; no race condition or special setup is needed. No attack requirements: the stale correlation row exists naturally after any event restriction. Low privileges: the attacker needs an authenticated account with read access to at least one event. No user interaction: the attacker initiates the search themselves. High vulnerability-component confidentiality impact: full attribute values and event metadata of restricted events are exposed. No integrity or availability impact on the vulnerable or subsequent components.

Weakness rationale
  • CWE-862 The correlation lookup path failed to enforce the current (live) authorization state of the target events and attributes. Access was granted based on a stale snapshot rather than the actual ACL, effectively missing the authorization check for restricted events.
  • CWE-284 The access control decision relied on outdated data (the distribution columns copied onto the correlation row) that did not reflect the current published/sharing-group state of the event, leading to improper access control.
Attack pattern rationale
  • CAPEC-114 The authorization state used for correlation lookups was incorrectly adjusted (stale) relative to the actual event ACL. An attacker with a legitimate account could exploit this misalignment to access data beyond their intended privilege scope. This is the closest CAPEC pattern; the exact mechanism is a stale authorization snapshot rather than a classic privilege-escalation primitive, so the mapping is approximate.
Assumptions to verify
  • The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 38 commits after fix); the exact first affected version is not stated in the patch.
  • CVSS PR:L assumes the attacker needs a standard authenticated MISP account with read access to at least one event; no evidence supports a lower or higher privilege requirement.
  • CAPEC-114 is the closest available pattern; the actual mechanism is a stale authorization snapshot rather than a classic privilege-escalation vector, so the mapping is approximate.
  • The patch does not specify whether the vulnerability requires the event to have been restricted after correlation creation, or whether other state changes (e.g., sharing group modification) also trigger the issue; the commit message mentions 'restricted' as the primary scenario.
  • No public exploit or PoC is referenced; exploitation status is assumed to be 'none'.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 7 11 medium 5
bcp-05-x-03
{
  "x_timeline": {
    "events": [
      {
        "description": "Corrective change authored (100235bd99b9f57a5a09976412d54e2001d2e0c4): fix: [security] Check correlations against the live event ACL",
        "id": "evt-fix-developed-1",
        "references": [
          "https://github.com/MISP/MISP/commit/100235bd9.patch"
        ],
        "timestamp": "2026-09-24T10:12:56Z",
        "type": "fix-developed"
      }
    ]
  }
}
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104912",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-03T15:48:11.201423Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-03T15:52:55.841Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "app/Model/Behavior/DefaultCorrelationBehavior.php"
          ],
          "product": "MISP",
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.48",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 5.5 (1M context)"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "elhoim"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\u003c/p\u003e\u003cp\u003eBecause the correlation row\u0027s distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with at least read access to some events in the instance.\u003c/p\u003e\u003cp\u003e- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\u003c/p\u003e\u003cp\u003eAffected versions: MISP prior to v2.5.48.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the live event access control list.\n\nBecause the correlation row\u0027s distribution columns are a point-in-time copy that lacks a published flag, the authorization check becomes incorrect when an event is subsequently restricted (for example, its sharing group is changed or it is unpublished). As a result, an authenticated user could retrieve attributes and event details belonging to events they no longer have permission to view.\n\nPreconditions:\n\n- An authenticated user with at least read access to some events in the instance.\n\n- The existence of correlations between events, at least one of which has been restricted after the correlation was created.\n\nImpact:\n\n- Confidentiality: exposure of attribute values and event metadata that the user is not authorized to access.\n\nAffected versions: MISP prior to v2.5.48."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-114",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-114 Exploiting Incorrectly Adjusted Privileges"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "SSVC",
          "other": {
            "content": {
              "options": [
                {
                  "Exploitation": "none"
                },
                {
                  "Automatable": "yes"
                },
                {
                  "Technical Impact": "partial"
                }
              ],
              "role": "Supplier",
              "timestamp": "2026-10-02T16:02:40Z",
              "version": "2.0.3"
            },
            "type": "SSVC"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862 Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-284",
              "description": "CWE-284 Improper Access Control",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T16:04:50.580Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/100235bd9"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.\u003c/p\u003e"
            }
          ],
          "value": "The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage."
        }
      ],
      "title": "MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata (v2.5.48, 38 commits after fix); the exact first affected version is not stated in the patch.",
                  "CVSS PR:L assumes the attacker needs a standard authenticated MISP account with read access to at least one event; no evidence supports a lower or higher privilege requirement.",
                  "CAPEC-114 is the closest available pattern; the actual mechanism is a stale authorization snapshot rather than a classic privilege-escalation vector, so the mapping is approximate.",
                  "The patch does not specify whether the vulnerability requires the event to have been restricted after correlation creation, or whether other state changes (e.g., sharing group modification) also trigger the issue; the commit message mentions \u0027restricted\u0027 as the primary scenario.",
                  "No public exploit or PoC is referenced; exploitation status is assumed to be \u0027none\u0027."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-114",
                    "rationale": "The authorization state used for correlation lookups was incorrectly adjusted (stale) relative to the actual event ACL. An attacker with a legitimate account could exploit this misalignment to access data beyond their intended privilege scope. This is the closest CAPEC pattern; the exact mechanism is a stale authorization snapshot rather than a classic privilege-escalation primitive, so the mapping is approximate."
                  }
                ],
                "commit": "100235bd99b9f57a5a09976412d54e2001d2e0c4",
                "confidence": "medium",
                "credits": [
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 5.5 (1M context)"
                  },
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "elhoim"
                  }
                ],
                "cvssRationale": "Network vector: MISP is a web application accessible over the network. Low complexity: the attacker simply performs a normal attribute search that triggers correlations; no race condition or special setup is needed. No attack requirements: the stale correlation row exists naturally after any event restriction. Low privileges: the attacker needs an authenticated account with read access to at least one event. No user interaction: the attacker initiates the search themselves. High vulnerability-component confidentiality impact: full attribute values and event metadata of restricted events are exposed. No integrity or availability impact on the vulnerable or subsequent components.",
                "fixSummary": "The fix ensures that correlation-based lookups are authorized against the live event and attribute access control lists rather than the stale distribution snapshot on the correlation row. A new filtering step validates related event IDs against the current event ACL before returning them, and attribute queries for non-admin users now include the live ACL conditions. Additionally, Event and Object fields are stripped from returned attribute results to prevent incidental metadata leakage.",
                "generatedAt": "2026-10-02T16:02:40.166976Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 11,
                      "assumptionCount": 5,
                      "confidence": "medium",
                      "model": "qwen3.8:27b",
                      "score": 7
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d",
                "patchSummary": "In DefaultCorrelationBehavior.php: (1) runGetRelatedAttributes now builds query conditions that include the live attribute ACL (buildConditions) for non-site-admin users, and ensures Event and Object are contained in the query for proper filtering; (2) after fetching related attributes, Event and Object sub-objects are unset from each result; (3) fetchRelatedEventIds now passes its results through a new __filterVisibleEventIds method that queries the Event model with createEventConditions to verify each event ID is still visible to the user; (4) the new __filterVisibleEventIds method returns the event IDs unchanged for site admins or empty lists, otherwise filters against the live event ACL.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "100235bd99b9f57a5a09976412d54e2001d2e0c4",
                    "date": "Thu, 24 Sep 2026 12:12:56 +0200",
                    "patchSha256": "a38b683420d93ff26d461badf81e0524bbd9618dd3dd6f187a994f5c5b47f23d",
                    "source": "https://github.com/MISP/MISP/commit/100235bd9.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/100235bd9.patch",
                    "subject": "fix: [security] Check correlations against the live event ACL"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/100235bd9.patch",
                "ssvc": {
                  "options": [
                    {
                      "Exploitation": "none"
                    },
                    {
                      "Automatable": "yes"
                    },
                    {
                      "Technical Impact": "partial"
                    }
                  ],
                  "role": "Supplier",
                  "timestamp": "2026-10-02T16:02:40Z",
                  "version": "2.0.3"
                },
                "subject": "fix: [security] Check correlations against the live event ACL",
                "tagVersionBoundary": {
                  "commits_after_fix": 38,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.48",
                  "version": "2.5.48",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-862",
                    "rationale": "The correlation lookup path failed to enforce the current (live) authorization state of the target events and attributes. Access was granted based on a stale snapshot rather than the actual ACL, effectively missing the authorization check for restricted events."
                  },
                  {
                    "cweId": "CWE-284",
                    "rationale": "The access control decision relied on outdated data (the distribution columns copied onto the correlation row) that did not reflect the current published/sharing-group state of the event, leading to improper access control."
                  }
                ]
              }
            },
            "bcp-05-x-03": {
              "x_timeline": {
                "events": [
                  {
                    "description": "Corrective change authored (100235bd99b9f57a5a09976412d54e2001d2e0c4): fix: [security] Check correlations against the live event ACL",
                    "id": "evt-fix-developed-1",
                    "references": [
                      "https://github.com/MISP/MISP/commit/100235bd9.patch"
                    ],
                    "timestamp": "2026-09-24T10:12:56Z",
                    "type": "fix-developed"
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20312"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-104912",
    "datePublished": "2026-10-02T16:04:50.580Z",
    "dateReserved": "2026-10-02T16:04:47.753Z",
    "dateUpdated": "2026-10-03T15:52:55.841Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104910 (GCVE-0-2026-104910)

Vulnerability from cvelistv5 – Published: 2026-10-02 16:01 – Updated: 2026-10-03 15:52
VLAI
Title
MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
Summary
MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event. The correlation table stores a snapshot of the event's distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts). Preconditions: - An authenticated user with access to at least one event in MISP. - The existence of correlation entries linking that event to other events the user should not be able to view. Impact: - Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access. - Potential reconnaissance of threat-intelligence event names and timelines across sharing groups. Affected: MISP versions prior to the fix commit (2ffa97f05).
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
Supplier · CIRCL (v2.0.3)
Decision recorded 2026-10-02 15:59 UTC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:48 UTC
CWE
References
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.48 (semver)
    cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Create a notification for this product.
GCVE extensions
AI involvement GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
Patch provenance GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-10-02 15:59
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/2ffa97f05.patch c315cbcd2cad…
Confidence
medium
Commit Subject Patch SHA-256
2ffa97f0526c fix: [security] Scope the related event list to what the c315cbcd2cad…
Fix summary

The fix enforces proper per-event authorization on the related events query by applying the user's full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.

Patch summary

In EventsController.php (viewRelatedEvents) and Event.php (getRelatedEvents), the query that fetches related event metadata previously used only Event.id IN (relatedEventIds) as the condition. The patch replaces this with a call to createEventConditions($user), which builds the full set of authorization conditions (published flag, distribution, sharing group), and then adds the Event.id filter on top. The stale comment claiming ACL was enforced via the correlation table was removed. Two files changed, 8 insertions, 9 deletions.

CVSS rationale

AV:N: MISP is a network-accessible web application. AC:L: An authenticated user simply requests the related events endpoint; no race condition or complex manipulation is needed. AT:N: No attack-target manipulation required. PR:L: Requires a low-privilege authenticated user with access to at least one event. UI:N: No user interaction needed. VC:L: Disclosure is limited to event metadata (title, date, correlation counts), not full event content or attributes. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No secondary impacts on other systems. The overall score reflects a low-severity information disclosure requiring authentication.

Weakness rationale
  • CWE-862 The related events query did not apply the caller's per-event authorization checks (published status, distribution, sharing group). The system relied on a stale snapshot in the correlation table instead of re-validating access, effectively omitting the authorization step for the returned events.
  • CWE-285 Even though some authorization existed (via the correlation table snapshot), it was based on outdated data and lacked the published flag check, making the authorization decision incorrect for events whose access parameters had changed or that were unpublished.
Attack pattern rationale
  • CAPEC-126 The attacker leverages the trusted correlation relationship stored in the correlation table. The system treated the correlation entry as a sufficient authorization basis, but the snapshot data was stale and incomplete (missing published flag), allowing access to event metadata the caller should not see. This is the closest CAPEC to the pattern of relying on a trusted data source that does not reflect current authorization state. Uncertainty: no CAPEC perfectly describes 'stale authorization snapshot in a join table'; CAPEC-126 is the best available match.
Assumptions to verify
  • The tag_version_boundary (v2.5.48, 50 commits after fix) is used as an approximate upper bound for affected versions; exact version boundaries are not explicitly stated in the patch metadata.
  • PR:L assumes the attacker needs only a basic authenticated MISP account with access to at least one event; higher-privilege roles may be required depending on deployment configuration, but the patch does not specify this.
  • VC:L assumes the disclosed metadata (event titles, dates, correlation counts) constitutes a low confidentiality impact; in highly sensitive threat-intelligence environments the impact could be rated higher.
  • CAPEC-126 is the closest available mapping; no CAPEC precisely describes authorization bypass via a stale snapshot in a correlation/join table.
  • The 'published' flag and distribution/sharing group checks are assumed to be the primary authorization mechanisms in MISP's event model, based on the commit message and patch context.
  • No public exploit or active exploitation is assumed; the patch does not reference any CVE, advisory, or exploitation evidence.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 6 11 medium 6
bcp-05-x-03
{
  "x_timeline": {
    "events": [
      {
        "description": "Corrective change authored (2ffa97f0526cd6579b91a4dea560f6246ecbe108): fix: [security] Scope the related event list to what the",
        "id": "evt-fix-developed-1",
        "references": [
          "https://github.com/MISP/MISP/commit/2ffa97f05.patch"
        ],
        "timestamp": "2026-09-22T13:14:32Z",
        "type": "fix-developed"
      }
    ]
  }
}
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104910",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-03T15:48:33.673589Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-03T15:52:56.095Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "EventsController (viewRelatedEvents)",
            "Event model (getRelatedEvents)"
          ],
          "product": "MISP",
          "programFiles": [
            "app/Controller/EventsController.php",
            "app/Model/Event.php"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.48",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Wenhao Wu"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 5 (1M context)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller\u0027s access rights against each related event.\u003c/p\u003e\u003cp\u003eThe correlation table stores a snapshot of the event\u0027s distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open\u2014because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded\u2014were still returned with their metadata (title, date, correlating value counts).\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with access to at least one event in MISP.\u003c/p\u003e\u003cp\u003e- The existence of correlation entries linking that event to other events the user should not be able to view.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.\u003c/p\u003e\u003cp\u003e- Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix commit (2ffa97f05).\u003c/p\u003e"
            }
          ],
          "value": "MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller\u0027s access rights against each related event.\n\nThe correlation table stores a snapshot of the event\u0027s distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open\u2014because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded\u2014were still returned with their metadata (title, date, correlating value counts).\n\nPreconditions:\n\n- An authenticated user with access to at least one event in MISP.\n\n- The existence of correlation entries linking that event to other events the user should not be able to view.\n\nImpact:\n\n- Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access.\n\n- Potential reconnaissance of threat-intelligence event names and timelines across sharing groups.\n\nAffected: MISP versions prior to the fix commit (2ffa97f05)."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-126",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-126 Leverage Trusted Relationship"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "SSVC",
          "other": {
            "content": {
              "options": [
                {
                  "Exploitation": "none"
                },
                {
                  "Automatable": "yes"
                },
                {
                  "Technical Impact": "partial"
                }
              ],
              "role": "Supplier",
              "timestamp": "2026-10-02T15:59:27Z",
              "version": "2.0.3"
            },
            "type": "SSVC"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862 Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-285",
              "description": "CWE-285 Improper Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T16:01:32.781Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/2ffa97f05"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.\u003c/p\u003e"
            }
          ],
          "value": "The fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list."
        }
      ],
      "title": "MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The tag_version_boundary (v2.5.48, 50 commits after fix) is used as an approximate upper bound for affected versions; exact version boundaries are not explicitly stated in the patch metadata.",
                  "PR:L assumes the attacker needs only a basic authenticated MISP account with access to at least one event; higher-privilege roles may be required depending on deployment configuration, but the patch does not specify this.",
                  "VC:L assumes the disclosed metadata (event titles, dates, correlation counts) constitutes a low confidentiality impact; in highly sensitive threat-intelligence environments the impact could be rated higher.",
                  "CAPEC-126 is the closest available mapping; no CAPEC precisely describes authorization bypass via a stale snapshot in a correlation/join table.",
                  "The \u0027published\u0027 flag and distribution/sharing group checks are assumed to be the primary authorization mechanisms in MISP\u0027s event model, based on the commit message and patch context.",
                  "No public exploit or active exploitation is assumed; the patch does not reference any CVE, advisory, or exploitation evidence."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-126",
                    "rationale": "The attacker leverages the trusted correlation relationship stored in the correlation table. The system treated the correlation entry as a sufficient authorization basis, but the snapshot data was stale and incomplete (missing published flag), allowing access to event metadata the caller should not see. This is the closest CAPEC to the pattern of relying on a trusted data source that does not reflect current authorization state. Uncertainty: no CAPEC perfectly describes \u0027stale authorization snapshot in a join table\u0027; CAPEC-126 is the best available match."
                  }
                ],
                "commit": "2ffa97f0526cd6579b91a4dea560f6246ecbe108",
                "confidence": "medium",
                "credits": [
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Wenhao Wu"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 5 (1M context)"
                  }
                ],
                "cvssRationale": "AV:N: MISP is a network-accessible web application. AC:L: An authenticated user simply requests the related events endpoint; no race condition or complex manipulation is needed. AT:N: No attack-target manipulation required. PR:L: Requires a low-privilege authenticated user with access to at least one event. UI:N: No user interaction needed. VC:L: Disclosure is limited to event metadata (title, date, correlation counts), not full event content or attributes. VI:N, VA:N: No integrity or availability impact. SC:N, SI:N, SA:N: No secondary impacts on other systems. The overall score reflects a low-severity information disclosure requiring authentication.",
                "fixSummary": "The fix enforces proper per-event authorization on the related events query by applying the user\u0027s full access-control conditions (including published status, distribution level, and sharing group membership) to the event lookup, rather than relying solely on the stale distribution snapshot stored in the correlation table. This ensures that only events the caller is currently permitted to read are returned in the related events list.",
                "generatedAt": "2026-10-02T15:59:27.212571Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 11,
                      "assumptionCount": 6,
                      "confidence": "medium",
                      "model": "qwen3.8:27b",
                      "score": 6
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "c315cbcd2cad3e0a5886680a4c6a903d9ed5f3fe3893670f74786cea77a56eb3",
                "patchSummary": "In EventsController.php (viewRelatedEvents) and Event.php (getRelatedEvents), the query that fetches related event metadata previously used only Event.id IN (relatedEventIds) as the condition. The patch replaces this with a call to createEventConditions($user), which builds the full set of authorization conditions (published flag, distribution, sharing group), and then adds the Event.id filter on top. The stale comment claiming ACL was enforced via the correlation table was removed. Two files changed, 8 insertions, 9 deletions.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "2ffa97f0526cd6579b91a4dea560f6246ecbe108",
                    "date": "Tue, 22 Sep 2026 15:14:32 +0200",
                    "patchSha256": "c315cbcd2cad3e0a5886680a4c6a903d9ed5f3fe3893670f74786cea77a56eb3",
                    "source": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
                    "subject": "fix: [security] Scope the related event list to what the"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/2ffa97f05.patch",
                "ssvc": {
                  "options": [
                    {
                      "Exploitation": "none"
                    },
                    {
                      "Automatable": "yes"
                    },
                    {
                      "Technical Impact": "partial"
                    }
                  ],
                  "role": "Supplier",
                  "timestamp": "2026-10-02T15:59:27Z",
                  "version": "2.0.3"
                },
                "subject": "fix: [security] Scope the related event list to what the",
                "tagVersionBoundary": {
                  "commits_after_fix": 50,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.48",
                  "version": "2.5.48",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-862",
                    "rationale": "The related events query did not apply the caller\u0027s per-event authorization checks (published status, distribution, sharing group). The system relied on a stale snapshot in the correlation table instead of re-validating access, effectively omitting the authorization step for the returned events."
                  },
                  {
                    "cweId": "CWE-285",
                    "rationale": "Even though some authorization existed (via the correlation table snapshot), it was based on outdated data and lacked the published flag check, making the authorization decision incorrect for events whose access parameters had changed or that were unpublished."
                  }
                ]
              }
            },
            "bcp-05-x-03": {
              "x_timeline": {
                "events": [
                  {
                    "description": "Corrective change authored (2ffa97f0526cd6579b91a4dea560f6246ecbe108): fix: [security] Scope the related event list to what the",
                    "id": "evt-fix-developed-1",
                    "references": [
                      "https://github.com/MISP/MISP/commit/2ffa97f05.patch"
                    ],
                    "timestamp": "2026-09-22T13:14:32Z",
                    "type": "fix-developed"
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20165"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-104910",
    "datePublished": "2026-10-02T16:01:32.781Z",
    "dateReserved": "2026-10-02T16:01:26.599Z",
    "dateUpdated": "2026-10-03T15:52:56.095Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104472 (GCVE-0-2026-104472)

Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 14:09
VLAI
Title
YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler
Summary
YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 14:08 UTC
CWE
References
Impacted products
Vendor Product Version
YesWiki yeswiki Affected: 0 , < 4.6.7 (semver)
Unaffected: 4.6.7 (semver)
    cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-01 00:00
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104472",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T14:08:58.660765Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T14:09:06.224Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-7cj2-9pgf-vcw2"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "yeswiki",
          "vendor": "YesWiki",
          "versions": [
            {
              "lessThan": "4.6.7",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.6.7",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "sondt99"
        }
      ],
      "datePublic": "2026-09-01T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request the download handler with a known page tag and file parameter to retrieve confidential attachments from read-restricted pages."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T11:38:36.710Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-7cj2-9pgf-vcw2)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-7cj2-9pgf-vcw2"
        },
        {
          "name": "VulnCheck Advisory: YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-missing-authorization-via-attachment-download-handler"
        }
      ],
      "title": "YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-104472",
    "datePublished": "2026-10-02T11:38:36.710Z",
    "dateReserved": "2026-10-02T00:55:58.387Z",
    "dateUpdated": "2026-10-02T14:09:06.224Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104467 (GCVE-0-2026-104467)

Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:15
VLAI
Title
YesWiki before 4.6.7 Authorization Bypass via Public API Mode
Summary
YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.
SSVC
Exploitation: poc Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 15:14 UTC
CWE
References
Impacted products
Vendor Product Version
YesWiki yeswiki Affected: 0 , < 4.6.7 (semver)
Unaffected: 4.6.7 (semver)
    cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-01 00:00
Credits
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104467",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T15:14:38.997682Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T15:15:54.625Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-v527-6r4j-j2w2"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "yeswiki",
          "vendor": "YesWiki",
          "versions": [
            {
              "lessThan": "4.6.7",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.6.7",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "sondt99"
        }
      ],
      "datePublic": "2026-09-01T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 9.2,
            "baseSeverity": "CRITICAL",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T11:38:33.480Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-v527-6r4j-j2w2)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-v527-6r4j-j2w2"
        },
        {
          "name": "VulnCheck Advisory: YesWiki before 4.6.7 Authorization Bypass via Public API Mode",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-authorization-bypass-via-public-api-mode"
        }
      ],
      "title": "YesWiki before 4.6.7 Authorization Bypass via Public API Mode",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-104467",
    "datePublished": "2026-10-02T11:38:33.480Z",
    "dateReserved": "2026-10-02T00:55:11.982Z",
    "dateUpdated": "2026-10-02T15:15:54.625Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104438 (GCVE-0-2026-104438)

Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:27
VLAI
Title
YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions
Summary
YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 15:25 UTC
CWE
References
Impacted products
Vendor Product Version
YesWiki yeswiki Affected: 0 , < 4.6.7 (semver)
Unaffected: 4.6.7 (semver)
    cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-31 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104438",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T15:25:16.963808Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T15:27:01.134Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-hx4v-hjvg-9p6w"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "yeswiki",
          "vendor": "YesWiki",
          "versions": [
            {
              "lessThan": "4.6.7",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.6.7",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.6.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "skeletonsec"
        }
      ],
      "datePublic": "2026-08-31T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T11:38:14.506Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-hx4v-hjvg-9p6w)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-hx4v-hjvg-9p6w"
        },
        {
          "name": "VulnCheck Advisory: YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-information-disclosure-via-listpagestag-and-includepages-actions"
        }
      ],
      "title": "YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-104438",
    "datePublished": "2026-10-02T11:38:14.506Z",
    "dateReserved": "2026-10-02T00:50:26.604Z",
    "dateUpdated": "2026-10-02T15:27:01.134Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104410 (GCVE-0-2026-104410)

Vulnerability from cvelistv5 – Published: 2026-10-02 11:37 – Updated: 2026-10-02 17:38
VLAI
Title
SiYuan before 3.8.5 Information Disclosure via /api/export/preview
Summary
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 17:37 UTC
CWE
References
Impacted products
Vendor Product Version
siyuan-note siyuan Affected: 0 , < 3.8.5 (semver)
Unaffected: 3.8.5 (semver)
    cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-17 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104410",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T17:37:34.990604Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T17:38:17.498Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-778g-gq49-fxxj"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:golang/github.com/siyuan-note/siyuan/kernel",
          "product": "siyuan",
          "vendor": "siyuan-note",
          "versions": [
            {
              "lessThan": "3.8.5",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.8.5",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "3.8.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "manus-pi"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "manus-use"
        }
      ],
      "datePublic": "2026-09-17T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows\u0027 primary-key text and cell values."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T11:37:54.829Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-778g-gq49-fxxj)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-778g-gq49-fxxj"
        },
        {
          "name": "VulnCheck Advisory: SiYuan before 3.8.5 Information Disclosure via /api/export/preview",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/siyuan-before-3.8.5-information-disclosure-via-api-export-preview"
        }
      ],
      "title": "SiYuan before 3.8.5 Information Disclosure via /api/export/preview",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-104410",
    "datePublished": "2026-10-02T11:37:54.829Z",
    "dateReserved": "2026-10-02T00:44:44.528Z",
    "dateUpdated": "2026-10-02T17:38:17.498Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-104054 (GCVE-0-2026-104054)

Vulnerability from cvelistv5 – Published: 2026-10-02 02:00 – Updated: 2026-10-02 19:52
VLAI
Title
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
Summary
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 19:52 UTC
CWE
References
URL Tags
https://vuldb.com/vuln/412762 vdb-entrytechnical-description
https://vuldb.com/vuln/412762/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-104054 third-party-advisory
https://vuldb.com/submit/959492 third-party-advisory
https://github.com/calcom/cal.diy/issues/29802 exploitissue-tracking
https://github.com/calcom/cal.diy/pull/30253 issue-trackingpatch
https://github.com/calcom/cal.diy/ product
Impacted products
Vendor Product Version
calcom cal.diy Affected: 6.0
Affected: 6.1
Affected: 6.2.0
    cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-104054",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-02T19:52:33.884677Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-02T19:52:48.259Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:calcom:cal.diy:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "PBAC Permission Engine"
          ],
          "product": "cal.diy",
          "vendor": "calcom",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "affected",
              "version": "6.2.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "geochen (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 6.5,
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T02:00:11.876Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412762 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412762"
        },
        {
          "name": "VDB-412762 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412762/cti"
        },
        {
          "name": "CVE-2026-104054 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-104054"
        },
        {
          "name": "Submit #959492 | https://github.com/calcom/ cal.diy commit 4026669 broken access control",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/959492"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/calcom/cal.diy/issues/29802"
        },
        {
          "tags": [
            "issue-tracking",
            "patch"
          ],
          "url": "https://github.com/calcom/cal.diy/pull/30253"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/calcom/cal.diy/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-10-01T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-10-01T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-10-01T20:02:21.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-104054",
    "datePublished": "2026-10-02T02:00:11.876Z",
    "dateReserved": "2026-10-01T17:57:14.224Z",
    "dateUpdated": "2026-10-02T19:52:48.259Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103762 (GCVE-0-2026-103762)

Vulnerability from cvelistv5 – Published: 2026-10-02 11:37 – Updated: 2026-10-02 11:37
VLAI
Title
SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints
Summary
SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time.
CWE
References
Impacted products
Vendor Product Version
siyuan-note siyuan Affected: 0 , < 3.8.5 (semver)
Unaffected: 3.8.5 (semver)
    cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-17 00:00
Credits
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:golang/github.com/siyuan-note/siyuan/kernel",
          "product": "siyuan",
          "vendor": "siyuan-note",
          "versions": [
            {
              "lessThan": "3.8.5",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.8.5",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "3.8.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "manus-pi"
        }
      ],
      "datePublic": "2026-09-17T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook\u0027s existence and creation time."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-02T11:37:53.531Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-2mrf-mx66-vv6g)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-2mrf-mx66-vv6g"
        },
        {
          "name": "VulnCheck Advisory: SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/siyuan-before-3.8.5-missing-authorization-in-save-path-resolver-endpoints"
        }
      ],
      "title": "SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103762",
    "datePublished": "2026-10-02T11:37:53.531Z",
    "dateReserved": "2026-10-01T10:39:47.845Z",
    "dateUpdated": "2026-10-02T11:37:53.531Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation
Architecture and Design
  • Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries.
  • Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
Mitigation
Architecture and Design

Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Mitigation MIT-4.4
Architecture and Design

Strategy: Libraries or Frameworks

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Mitigation
Architecture and Design
  • For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
  • One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.
Mitigation
System Configuration Installation

Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.

CAPEC-665: Exploitation of Thunderbolt Protection Flaws

An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate Thunderbolt controller firmware in order to exploit vulnerabilities in the implementation of authorization and verification schemes within Thunderbolt protection mechanisms. Upon gaining physical access to a target device, the adversary conducts high-level firmware manipulation of the victim Thunderbolt controller SPI (Serial Peripheral Interface) flash, through the use of a SPI Programing device and an external Thunderbolt device, typically as the target device is booting up. If successful, this allows the adversary to modify memory, subvert authentication mechanisms, spoof identities and content, and extract data and memory from the target device. Currently 7 major vulnerabilities exist within Thunderbolt protocol with 9 attack vectors as noted in the Execution Flow.