CVE-2026-103239 Details
Description
MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48
A privilege escalation vulnerability has been identified in MISP versions prior to 2.5.48. This issue arises in the tag collection creation and editing features, where the full HTTP request payload is accepted and processed. A user with tag editor permissions could inject additional model data, such as User or Organisation records, into the payload. The bulk-association save operation then indiscriminately wrote this injected data into the database, allowing the attacker to modify or create privileged accounts and escalate their privileges to that of a site administrator.
Users can update to MISP version 2.5.48 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/MISP/commit/96f735e7b | CIRCL | Source CodeVendor |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| MISP | < 2.5.48 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | CIRCL |
Volerion