MISP contains a mass assignment vulnerability in the event delegation feature. (CVE-2026-103235)
MISP has a mass assignment vulnerability in its event delegation feature affecting versions prior to 2.5.48. Authenticated users with delegation permission can manipulate delegation records to gain unauthorized read access to arbitrary events and potentially transfer event ownership. This vulnerability allows overwriting existing delegation records and unauthorized event access across organizations.
AI Analysis
Technical Summary
The vulnerability in MISP's event delegation feature allows an authenticated user with delegation permission to submit a delegation request that includes caller-supplied fields such as primary key and event_id. The application authorizes the user against the event in the URL but persists the entire submitted record, enabling the attacker to retarget delegation records to any event on the instance. This grants read access to arbitrary events belonging to other organizations and can lead to event ownership transfer if the target organization accepts the delegation. The vulnerability affects MISP versions before 2.5.48 and requires the MISP.delegation server setting to be enabled.
Potential Impact
An attacker with delegation permission can gain unauthorized read access to any event on the MISP instance, violating confidentiality. Additionally, the attacker can overwrite existing delegation records and transfer event ownership, impacting data integrity. This could lead to unauthorized data exposure and manipulation of event ownership across organizations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict delegation permissions to trusted users only and consider disabling the MISP.delegation server setting if not required.
MISP contains a mass assignment vulnerability in the event delegation feature. (CVE-2026-103235)
Description
MISP has a mass assignment vulnerability in its event delegation feature affecting versions prior to 2.5.48. Authenticated users with delegation permission can manipulate delegation records to gain unauthorized read access to arbitrary events and potentially transfer event ownership. This vulnerability allows overwriting existing delegation records and unauthorized event access across organizations.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in MISP's event delegation feature allows an authenticated user with delegation permission to submit a delegation request that includes caller-supplied fields such as primary key and event_id. The application authorizes the user against the event in the URL but persists the entire submitted record, enabling the attacker to retarget delegation records to any event on the instance. This grants read access to arbitrary events belonging to other organizations and can lead to event ownership transfer if the target organization accepts the delegation. The vulnerability affects MISP versions before 2.5.48 and requires the MISP.delegation server setting to be enabled.
Potential Impact
An attacker with delegation permission can gain unauthorized read access to any event on the MISP instance, violating confidentiality. Additionally, the attacker can overwrite existing delegation records and transfer event ownership, impacting data integrity. This could lead to unauthorized data exposure and manipulation of event ownership across organizations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict delegation permissions to trusted users only and consider disabling the MISP.delegation server setting if not required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j2mf-q9c3-gwxw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-103235"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6abd30792a4e24523d33ffc7
Added to database: 09/30/2026, 15:53:29 UTC
Last enriched: 09/30/2026, 15:56:30 UTC
Last updated: 10/01/2026, 05:08:50 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.