Impact
MISP suffered a mass‑assignment flaw in its event delegation feature. When an authenticated user with delegation authority submits a delegation request, the application validates the user against the event mentioned in the URL but then stores the entire request payload, including user supplied values for the primary key and event_id. Because those values can be overwritten, an attacker can redirect an existing delegation record to any event on the instance. The directed event then grants the requester’s organization read rights to that event, and if the recipient organization accepts the delegation the original event ownership is transferred and the old record deleted. Consequently an attacker can expose confidential event data from other organisations and alter event ownership, effectively compromising data integrity and confidentiality.
Affected Systems
This vulnerability affects the MISP threat‑intel platform, specifically versions earlier than 2.5.48. The flaw is present in the MISP event delegation functionality exposed by the web interface and relies on the MISP.delegation server setting being enabled.
Risk and Exploitability
The CVSS score for this issue is 8.7, indicating high severity. EPSS data is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated with delegation permission (perm_delegate) and the server setting must be enabled, implying a local or authenticated web‑attack vector. Once those conditions are met, the vulnerability can be leveraged to read arbitrary events and, if the target organisation accepts the delegation, to transfer ownership of those events. The lack of an EPSS score suggests an unknown exploitation rate, but the high CVSS points to a significant risk if the issue is left unresolved.
OpenCVE Enrichment