Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103239— MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection

Quick assessment

Affected
MISP MISP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MISP 存在一个权限提升漏洞,位于标签集合(tag collection)的创建和编辑功能中。受影响的操作会接收完整的 HTTP 请求负载,并将其传递给批量关联保存操作(bulk-association save operation)。该操作不仅会写入预期的标签集合记录,还会将请求负载中存在的任何关联模型数据一并写入数据库。 拥有“标签编辑器”(tag editor)权限的用户可以构造一个请求,在包含标签集合字段的同时,额外注入其他模型数据(例如 User 或 Organisation 记录)。由于该保存操作不加

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103239

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
Source: CVE Program / CVE List V5
Vulnerability Description
MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-103239

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103239

请登录查看更多情报信息。

Other References for CVE-2026-103239 (1)

Same Patch Batch · MISP · 2026-09-30 · 3 CVEs total

CVE-2026-103235 8.7 HIGH MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events
CVE-2026-103237 8.3 HIGH MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows

IV. Related Vulnerabilities

V. Comments for CVE-2026-103239

No comments yet


Leave a comment