Description
MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off.

However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.

Impact:

- A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.

- A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.

- A user could reassign a model's organisation to an arbitrary value.

Preconditions:

- Authenticated user with decaying-model permission (perm_decaying).

- Network access to the MISP instance.

Affected: <2.5.48.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized cross-organization model overwrite and default flag manipulation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the decaying model import endpoint, where only top‑level identifiers are stripped and the organization ID and default flag are hard‑coded for the outer array. An attacker with decaying‑model permissions can submit a nested model key that contains its own primary key, organization identifier, and default flag. Because the application does not properly filter these nested keys, the ORM reads them as part of the model and can overwrite an existing decaying model belonging to another organization, set that model as the organization default, or reassign it to a different organization.

Affected Systems

MISP, version 2.5.48 and earlier. The vulnerability is present in all MISP releases prior to 2.5.48.

Risk and Exploitability

An attacker must be authenticated with the perm_decaying permission and have network access to the MISP instance. With these prerequisites, the attacker can submit a crafted decaying‑model import request that exploits the unchecked nested keys, resulting in model overwrite, altered default status, or re‑assignment. The CVSS score of 7.1 indicates a high severity, but the EPSS score is not available and KEV does not list this vulnerability. Nonetheless, because the exploit requires only standard network access and legitimate authentication, it poses a significant risk to organizations that allow the perm_decaying permission to non‑trusted users.

Generated by OpenCVE AI on October 2, 2026 at 17:38 UTC.

Remediation

Vendor Solution

The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.


OpenCVE Recommended Actions

  • Apply the latest MISP update that enforces an explicit allow‑list for the decaying model import and removes nested key processing.
  • Revoke the perm_decaying permission from all users except trusted administrators until the patch is applied to limit the attack surface.
  • Test the import endpoint with a crafted payload containing nested properties to ensure the new allow‑list rejects them and that models cannot be overwritten across organizations.

Generated by OpenCVE AI on October 2, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected: <2.5.48.
Title MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CWE-915
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:19:17.687Z

Reserved: 2026-10-02T15:56:12.330Z

Link: CVE-2026-104908

cve-icon Vulnrichment

Updated: 2026-10-02T16:19:08.415Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.580

Modified: 2026-10-02T17:17:05.017

Link: CVE-2026-104908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes