Description
MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.

A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.

Preconditions:

- An authenticated account with the tag editor permission (perm_tag_editor)

- Network access to the MISP instance

Impact:

- Unauthorized creation or modification of User and Organisation records

- Privilege escalation from tag editor to site administrator

Affected versions: < 2.5.48
Published: 2026-09-30
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A privilege escalation flaw exists in the tag collection creation and editing functionality of MISP. During these operations, the server accepts the entire HTTP request payload and forwards it to a bulk-association save call. That call writes not only the intended tag collection record but also all associated sibling model data that may be included in the request. A user with tag editor permissions can craft a payload that supplies User or Organisation records, which are then written to the database. This permits an attacker to create or modify privileged accounts and ultimately gain site administrator rights. The weakness is a broken access control (CWE‑284) coupled with missing authorization checks (CWE‑862).

Affected Systems

The vulnerability applies to all MISP installations running versions older than 2.5.48. It is specifically relevant for deployments of the MISP platform obtained from the official source or from its GitHub repository.

Risk and Exploitability

The CVSS score of 8.6 classifies this as a high‑severity vulnerability. Exploitation requires an authenticated MISP user with the perm_tag_editor capability and network access to the affected instance. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over HTTP, with the attacker sending crafted POST data to the tag collection endpoint. Once the vulnerable bulk‑save is invoked, the attacker’s supplied sibling records are persisted, enabling privilege escalation. Given the high severity and the necessity of authorization, the risk to affected deployments is significant.

Generated by OpenCVE AI on September 30, 2026 at 11:46 UTC.

Remediation

Vendor Solution

The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.


OpenCVE Recommended Actions

  • Apply the vendor patch that replaces the bulk‑association save with a two‑step process, ensuring that only tag collection data is saved and sibling model data is discarded
  • If the patch is not immediately available, consider rolling back to a stable MISP release newer than 2.5.48 or disabling the tag editor permission for untrusted accounts
  • Audit existing User and Organisation records for unintended or recent changes and review authentication logs for suspicious activity

Generated by OpenCVE AI on September 30, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48
Title MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
First Time appeared Misp
Misp misp
Weaknesses CWE-284
CWE-862
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-30T16:50:57.400Z

Reserved: 2026-09-30T10:16:15.941Z

Link: CVE-2026-103239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T11:16:43.527

Modified: 2026-09-30T11:16:43.637

Link: CVE-2026-103239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses