Mass Assignment Vulnerability in MISP Event Delegation Feature
CVE-2026-103235

8.7HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103235?

A mass assignment vulnerability exists in the event delegation feature of MISP. When users with delegation permissions submit a request, the application inadvertently authorizes the user against the designated event URL while allowing the entire payload, including sensitive fields like primary key and event_id, to be persisted. This flaw allows an authenticated attacker to manipulate the delegation payload and potentially gain read access to any event within the instance by re-targeting delegation records. If accepted by the target organization, this action could also overwrite existing delegation records, leading to unauthorized event ownership transfer and loss of integrity across event data.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 5
.