CVE Explorer
CVE-2026-10863
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending on how the value was processed by the underlying data access layer, this could allow manipulation of database query ordering and potentially expose the application to unsafe query construction.
The patch removes order f
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"misp","vendor":"misp","versions":[{"lessThanOrEqual":"2.5.38","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ada4996254f350635cd571392520bf1eb0a9e8148072cdfe5993bf8dc2583b2f · sha256:6a853bf782fe4812… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.4,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ada4996254f350635cd571392520bf1eb0a9e8148072cdfe5993bf8dc2583b2f · sha256:6a853bf782fe4812… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ada4996254f350635cd571392520bf1eb0a9e8148072cdfe5993bf8dc2583b2f · sha256:6a853bf782fe4812… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["patch"],"url":"https://github.com/MISP/MISP/commit/aa094a335ba2855f8a42a1dc44398f43560fe247"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ada4996254f350635cd571392520bf1eb0a9e8148072cdfe5993bf8dc2583b2f · sha256:6a853bf782fe4812… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.