CVE-2026-103235
Deferred Deferred - Pending Action

Mass Assignment in MISP Event Delegation

Vulnerability report for CVE-2026-103235, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CIRCL

Description

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has a mass assignment vulnerability in its event delegation feature. When a user with delegation permission submits a request, the application checks authorization against the event ID in the URL but then saves the entire delegation record, including user-supplied fields like primary key and event_id. This allows an attacker to inject values that retarget an existing delegation record to any event, granting unauthorized read access to events belonging to other organizations.

Detection Guidance

To detect this vulnerability, check for unauthorized delegation records in your MISP instance. Review delegation requests for unexpected event_id or primary key values. Use MISP's API or database queries to list delegations and verify their integrity. Ensure the MISP.delegation setting is disabled if not needed.

Impact Analysis

An authenticated attacker could gain read access to any event on the MISP instance, even those belonging to other organizations. They could also overwrite existing delegation records and transfer event ownership, potentially leading to unauthorized data exposure or loss of control over events.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in data breaches, non-compliance with access control policies, and potential legal consequences due to unauthorized data exposure.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to address the mass assignment vulnerability in the event delegation feature. Ensure the MISP.delegation server setting is disabled if not required. Review delegation permissions to confirm only authorized users have the perm_delegate permission.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103235. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart