CVE-2026-104908High· 7.1▾ TwilightMISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the def…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off.
However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.
Impact:
A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.
A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.
A user could reassign a model's organisation to an arbitrary value.
Preconditions:
Authenticated user with decaying-model permission (perm_decaying).
Network access to the MISP instance.
Affected: <2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104910Medium· 5.3MISP contains an authorization bypass in the related events listing functionality
CVE-2026-103858Medium· 5.3MISP contains an incomplete authorization check in the discussion posting functionality
CVE-2026-103659High· 7.1MISP contains an authorization bypass in the event flattening feature
CVE-2026-103235High· 8.7MISP contains a mass assignment vulnerability in the event delegation feature
CVE-2026-95805Medium· 5.3A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabl…
CVE-2026-95754Medium· 6.9In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list