MISP 在衰减模型(decaying model)导入功能中存在不正确的输入验证漏洞。导入端点本意是创建一个仅属于导入用户所属组织的衰减模型,并将默认标志(default flag)强制设置为关闭状态。 然而,应用程序仅在保存扁平化数据前剥离了顶层的 和 字段,并将外层数组中的 (组织标识)和 (默认标志)固定,但未对嵌套结构进行充分校验。具有衰减模型权限的用户可以提供一个包含其自身主键、组织标识符和默认标志的嵌套模型键(nested model key),从而绕过保存操作中的这些安全限制。 影响: 拥有 权限的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104912 | 7.1 HIGH | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data |
| CVE-2026-104906 | 6.2 MEDIUM | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
| CVE-2026-104900 | 5.3 MEDIUM | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
| CVE-2026-104910 | 5.3 MEDIUM | MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization |
| CVE-2026-104914 | 5.3 MEDIUM | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Pa |
| CVE-2026-104901 | 5.1 MEDIUM | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Serv |
| CVE-2026-104907 | 4.8 MEDIUM | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
No comments yet