Skip to main content

MISP contains a validation flaw in its object synchronization logic. (CVE-2026-107278)

0
Medium
Published: 10/07/2026 (10/07/2026, 18:32:09 UTC)
Source: GCVE Database

Description

MISP has a validation flaw in its object synchronization logic where objects created without a description are rejected by receiving instances during synchronization. This causes the receiving instance to silently drop the object and its attributes, resulting in loss of threat-intelligence data. The issue occurs when multiple MISP instances synchronize and an authorized user creates an object without a description. It is not exploitable externally but can cause unintended data loss within the sync topology. The affected versions are those prior to 2.5.48.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
Scope
X
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected software

GitHub Actionsmore threats →ai
misp/MISP
pkg:github/misp/MISP
Affected versions
<2.5.48

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 22:10:26 UTC

Technical Analysis

MISP contains a validation flaw in its object synchronization mechanism. When a MISP Object is created without a description on one instance, it is stored correctly there but rejected by the validation rules on receiving instances during synchronization. The receiving instances silently discard the object and all associated attributes due to the empty description field. This leads to loss of valid threat-intelligence data across synchronized MISP instances. The flaw requires that multiple MISP instances be configured to sync and that an authorized user create an object without a description. The issue affects versions prior to 2.5.48.

Potential Impact

Valid MISP objects and their attributes can be silently discarded on receiving instances during synchronization if the object lacks a description. This causes data-integrity loss in the threat-intelligence pipeline. The flaw is not externally exploitable but can be triggered by any authorized user with object-creation privileges, resulting in unintended data loss across the sync topology.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, ensure that all created MISP objects include a description to avoid silent data loss during synchronization.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-3fqm-jh2r-j26f
Osv Schema Version
1.4.0
Aliases
["CVE-2026-107278"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6ac6bff72cdf04f6568290be

Added to database: 10/07/2026, 21:56:07 UTC

Last enriched: 10/07/2026, 22:10:26 UTC

Last updated: 10/07/2026, 22:28:24 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses