MISP contains a validation flaw in its object synchronization logic. (CVE-2026-107278)
Description
MISP has a validation flaw in its object synchronization logic where objects created without a description are rejected by receiving instances during synchronization. This causes the receiving instance to silently drop the object and its attributes, resulting in loss of threat-intelligence data. The issue occurs when multiple MISP instances synchronize and an authorized user creates an object without a description. It is not exploitable externally but can cause unintended data loss within the sync topology. The affected versions are those prior to 2.5.48.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MISP contains a validation flaw in its object synchronization mechanism. When a MISP Object is created without a description on one instance, it is stored correctly there but rejected by the validation rules on receiving instances during synchronization. The receiving instances silently discard the object and all associated attributes due to the empty description field. This leads to loss of valid threat-intelligence data across synchronized MISP instances. The flaw requires that multiple MISP instances be configured to sync and that an authorized user create an object without a description. The issue affects versions prior to 2.5.48.
Potential Impact
Valid MISP objects and their attributes can be silently discarded on receiving instances during synchronization if the object lacks a description. This causes data-integrity loss in the threat-intelligence pipeline. The flaw is not externally exploitable but can be triggered by any authorized user with object-creation privileges, resulting in unintended data loss across the sync topology.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, ensure that all created MISP objects include a description to avoid silent data loss during synchronization.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3fqm-jh2r-j26f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-107278"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6ac6bff72cdf04f6568290be
Added to database: 10/07/2026, 21:56:07 UTC
Last enriched: 10/07/2026, 22:10:26 UTC
Last updated: 10/07/2026, 22:28:24 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.