CVE-2026-104908
Deferred Deferred - Pending Action

Improper Input Validation in MISP Decaying Model Import

Vulnerability report for CVE-2026-104908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: CIRCL

Description

MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected: <2.5.48.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
misp misp to 2.5.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MISP has an improper input validation flaw in the decaying model import feature. The system was designed to create new models exclusively for the importing user's organization with the default flag off. However, it only removed top-level ID and UUID fields while saving data flat, allowing nested models to bypass security checks. A user with decaying-model permissions could manipulate nested keys to overwrite another organization's model, change ownership, or set a model as default.

Detection Guidance

To detect this vulnerability, check MISP instances running versions before 2.5.48 for unauthorized modifications to decaying models. Review logs for import operations with nested DecayingModel keys containing unexpected org_id or default flags. Inspect model ownership changes or default flag assignments not matching the importing user's organization.

Impact Analysis

If you have perm_decaying access, an attacker could overwrite your organization's decaying models, altering scoring behavior or ownership. They could also create default models affecting other users' data or reassign models to arbitrary organizations. This requires network access to the MISP instance and valid credentials.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized users to modify or overwrite decaying models used for data scoring or analysis. If such models are used in processing personal or health data, unauthorized changes could lead to incorrect data handling, violating integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Update MISP to version 2.5.48 or later to address the improper input validation in decaying model import functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart