Impact
The vulnerability exists in the decaying model import endpoint, where only top‑level identifiers are stripped and the organization ID and default flag are hard‑coded for the outer array. An attacker with decaying‑model permissions can submit a nested model key that contains its own primary key, organization identifier, and default flag. Because the application does not properly filter these nested keys, the ORM reads them as part of the model and can overwrite an existing decaying model belonging to another organization, set that model as the organization default, or reassign it to a different organization.
Affected Systems
MISP, version 2.5.48 and earlier. The vulnerability is present in all MISP releases prior to 2.5.48.
Risk and Exploitability
An attacker must be authenticated with the perm_decaying permission and have network access to the MISP instance. With these prerequisites, the attacker can submit a crafted decaying‑model import request that exploits the unchecked nested keys, resulting in model overwrite, altered default status, or re‑assignment. The CVSS score of 7.1 indicates a high severity, but the EPSS score is not available and KEV does not list this vulnerability. Nonetheless, because the exploit requires only standard network access and legitimate authentication, it poses a significant risk to organizations that allow the perm_decaying permission to non‑trusted users.
OpenCVE Enrichment