Get real-time updates on Telegram
Verified
CVE-2026-107175: MISP 0 to before 2.5.48
Affected technology
MISP · 0 to before 2.5.48
MISP
Component: Event model (app/Model/Event.php), Correlation engine
File: app/Model/Event.php
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could access information they should not be able to access under the conditions described by the source. Source advisory’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality, integrity and availability impact as none.
- CWE
- CWE-284, CWE-665
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 13:38:49.647974+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107175.html