CVE-2026-103235High· 8.7▾ TwilightMISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then pers…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.
An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.
Preconditions:
An authenticated user with the delegation permission (perm_delegate)
The MISP.delegation server setting must be enabled
Impact:
Confidentiality: read access to any event on the instance
Integrity: overwriting existing delegation records and transferring event ownership
Affected versions: MISP < 2.5.48
MISP < 2.5.48The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103237High· 8.3MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows
CVE-2026-95683Medium· 5.3In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes
CVE-2026-94393Medium· 6.4When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…
CVE-2026-94374High· 8.3MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model
CVE-2026-91846High· 7.1Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…
CVE-2026-95806High· 7.7MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: - any fil…