Improper Input Validation in MISP's Decaying Model Import Functionality
CVE-2026-104908

7.1HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104908?

MISP suffers from an improper input validation issue within its decaying model import feature. This vulnerability allows a user with decaying-model permissions to manipulate the import process, potentially overwriting existing decaying models belonging to different organizations. Users can insert nested model keys with their own identifiers, compromising the integrity of the data. As a result, attackers can alter model attributes, including names, formulas, and ownership, while also having the capability to designate a decaying model as the organization default, leading to unintended scoring impacts for other users. Affected systems should be patched promptly to mitigate these risks.

Affected Version(s)

MISP 0 < 2.5.48

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
iglocska
Claude Opus 5
.