CVE-2026-103237
Deferred Deferred - Pending Action

Improper Input Validation in MISP Leading to Cross-Tenant Data Integrity Issues

Vulnerability report for CVE-2026-103237, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CIRCL

Description

MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller's context. However, the underlying ORM's set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields. An authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to. Impact: - Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted) - Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute - Requires only a low-privilege authenticated account with perm_add Affected versions: <2.5.48

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an improper input validation flaw in its ORM save path. When users submit data through endpoints like attribute add/edit or event edit, the application tries to sanitize the request by removing primary keys and locking records to the user's context. However, the ORM prioritizes nested keys matching the model alias, allowing attackers to embed malicious nested blocks that bypass sanitization. This lets authenticated users with basic write permissions overwrite, re-parent, or delete rows belonging to other organizations or events they shouldn't access.

The vulnerability occurs because the ORM's set() method discards outer scalar fields when a nested key matches the model alias, enabling attackers to manipulate database rows through crafted requests.

Detection Guidance

This vulnerability cannot be directly detected through network or system commands as it is a logic flaw in the MISP application's input validation and ORM handling. The issue requires code-level inspection or monitoring for unauthorized data modifications in the MISP database. Reviewing the MISP logs for suspicious activity such as unexpected changes to attributes, objects, or events by low-privilege users may indicate exploitation.

Impact Analysis

An attacker with a low-privilege account could modify or delete data they shouldn't access, such as changing attribute values, re-parenting objects to different events, or soft-deleting rows across the system. This could corrupt data integrity, disrupt operations, or lead to unauthorized information exposure.

Compliance Impact

This vulnerability could lead to unauthorized data modifications or deletions, violating integrity and confidentiality requirements in GDPR and HIPAA. It may result in unauthorized access to sensitive data, improper data handling, or failure to maintain accurate records, potentially leading to compliance violations and legal consequences.

Mitigation Strategies

Upgrade MISP to version 2.5.48 or later to address the improper input validation vulnerability in the ORM save path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103237. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart