MISP contains an improper input validation vulnerability in its ORM save path. (CVE-2026-103237)
MISP contains an improper input validation vulnerability in its ORM save path that allows an authenticated user with low-level write permissions to manipulate nested input data. This flaw enables attackers to overwrite, re-parent, or soft-delete database rows belonging to other organizations or events without read access. The vulnerability affects multiple entity types including Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute. It impacts versions prior to 2.5.48.
AI Analysis
Technical Summary
The vulnerability arises because MISP sanitizes the outer record by stripping primary keys and pinning event_id or object_id to the caller's context, but the ORM's set() method prioritizes nested keys matching the model alias. An attacker can embed a nested block under the model alias key with attacker-chosen id and event_id values, bypassing sanitization and allowing unauthorized modification of data across tenants. This requires only a low-privilege authenticated user with perm_add rights and affects multiple entity types. The affected versions are all versions prior to 2.5.48.
Potential Impact
An attacker with low-privilege authenticated access can compromise cross-tenant data integrity by rewriting attribute values, re-parenting objects to attacker-controlled events, or soft-deleting rows belonging to other organizations or events. This undermines data isolation and integrity across tenants in MISP, potentially affecting multiple entity types.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict write permissions to trusted users and monitor for suspicious activity related to nested input data manipulation.
MISP contains an improper input validation vulnerability in its ORM save path. (CVE-2026-103237)
Description
MISP contains an improper input validation vulnerability in its ORM save path that allows an authenticated user with low-level write permissions to manipulate nested input data. This flaw enables attackers to overwrite, re-parent, or soft-delete database rows belonging to other organizations or events without read access. The vulnerability affects multiple entity types including Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute. It impacts versions prior to 2.5.48.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because MISP sanitizes the outer record by stripping primary keys and pinning event_id or object_id to the caller's context, but the ORM's set() method prioritizes nested keys matching the model alias. An attacker can embed a nested block under the model alias key with attacker-chosen id and event_id values, bypassing sanitization and allowing unauthorized modification of data across tenants. This requires only a low-privilege authenticated user with perm_add rights and affects multiple entity types. The affected versions are all versions prior to 2.5.48.
Potential Impact
An attacker with low-privilege authenticated access can compromise cross-tenant data integrity by rewriting attribute values, re-parenting objects to attacker-controlled events, or soft-deleting rows belonging to other organizations or events. This undermines data isolation and integrity across tenants in MISP, potentially affecting multiple entity types.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict write permissions to trusted users and monitor for suspicious activity related to nested input data manipulation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-52c6-qg88-jh84
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-103237"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6abd30792a4e24523d33ffc2
Added to database: 09/30/2026, 15:53:29 UTC
Last enriched: 09/30/2026, 15:56:18 UTC
Last updated: 10/01/2026, 05:08:50 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.