Mass Assignment Vulnerability in MISP Event Delegation Feature
CVE-2026-103235
8.7HIGH
What is CVE-2026-103235?
A mass assignment vulnerability exists in the event delegation feature of MISP. When users with delegation permissions submit a request, the application inadvertently authorizes the user against the designated event URL while allowing the entire payload, including sensitive fields like primary key and event_id, to be persisted. This flaw allows an authenticated attacker to manipulate the delegation payload and potentially gain read access to any event within the instance by re-targeting delegation records. If accepted by the target organization, this action could also overwrite existing delegation records, leading to unauthorized event ownership transfer and loss of integrity across event data.
Affected Version(s)
MISP 0 < 2.5.48
