Impact
A privilege escalation flaw exists in the tag collection creation and editing functionality of MISP. During these operations, the server accepts the entire HTTP request payload and forwards it to a bulk-association save call. That call writes not only the intended tag collection record but also all associated sibling model data that may be included in the request. A user with tag editor permissions can craft a payload that supplies User or Organisation records, which are then written to the database. This permits an attacker to create or modify privileged accounts and ultimately gain site administrator rights. The weakness is a broken access control (CWE‑284) coupled with missing authorization checks (CWE‑862).
Affected Systems
The vulnerability applies to all MISP installations running versions older than 2.5.48. It is specifically relevant for deployments of the MISP platform obtained from the official source or from its GitHub repository.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high‑severity vulnerability. Exploitation requires an authenticated MISP user with the perm_tag_editor capability and network access to the affected instance. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over HTTP, with the attacker sending crafted POST data to the tag collection endpoint. Once the vulnerable bulk‑save is invoked, the attacker’s supplied sibling records are persisted, enabling privilege escalation. Given the high severity and the necessity of authorization, the risk to affected deployments is significant.
OpenCVE Enrichment