目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-104908— MISP衰减模型导入存在越权覆盖及默认标记漏洞

一分钟漏洞结论

影响对象
MISP MISP
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

MISP 在衰减模型(decaying model)导入功能中存在不正确的输入验证漏洞。导入端点本意是创建一个仅属于导入用户所属组织的衰减模型,并将默认标志(default flag)强制设置为关闭状态。 然而,应用程序仅在保存扁平化数据前剥离了顶层的 和 字段,并将外层数组中的 (组织标识)和 (默认标志)固定,但未对嵌套结构进行充分校验。具有衰减模型权限的用户可以提供一个包含其自身主键、组织标识符和默认标志的嵌套模型键(nested model key),从而绕过保存操作中的这些安全限制。 影响: 拥有 权限的

CVSS 7.1 · High

影响版本矩阵 1

厂商产品 版本范围状态
MISP MISP < 2.5.48 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-104908 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging
来源: CVE Program / CVE List V5
Vulnerability Description
MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected: <2.5.48.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
CWE-915
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
MISP MISP 0 ~ 2.5.48 cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

二、漏洞 CVE-2026-104908 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-104908 的情报信息

请登录查看更多情报信息。

CVE-2026-104908 补丁与修复 (1)

同批安全公告 · MISP · 2026-10-02 · 共 8 条

CVE-2026-104912 7.1 HIGH MISP 关联认证绕过致敏感数据泄露
CVE-2026-104906 6.2 MEDIUM MISP TAXII Object Viewer 存储型跨站脚本漏洞
CVE-2026-104900 5.3 MEDIUM MISP 远程事件预览索引未转义计数字段存储型XSS漏洞
CVE-2026-104910 5.3 MEDIUM MISP 事件列表绕过权限导致信息泄露漏洞
CVE-2026-104914 5.3 MEDIUM MISP 软件被删属性通过搜索和分页视图暴露漏洞
CVE-2026-104901 5.1 MEDIUM MISP ID Translator 远程事件 ID 未转义导致跨站脚本漏洞
CVE-2026-104907 4.8 MEDIUM MISP 事件预览内联处理程序远程标签ID JavaScript注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-104908

暂无评论


发表评论