CVE-2026-103235: MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events

Published Sep 30, 2026
·
Updated

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and eventid.

An authenticated attacker could inject a primary key or eventid into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.

Preconditions:

- An authenticated user with the delegation permission (permdelegate)

- The MISP.delegation server setting must be enabled

Impact:

- Confidentiality: read access to any event on the instance

- Integrity: overwriting existing delegation records and transferring event ownership

Affected versions: MISP < 2.5.48

Affected Software

1 affected component
Misp Misp<2.5.48

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in 2.5.48

Event History

Sep 30, 2026
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated, have the perm_delegate permission, and be able to use an instance where the MISP.delegation setting is enabled. Users without that permission do not meet the stated preconditions.

2

What access could exploitation provide?

The attacker can retarget a delegation record to arbitrary events on the instance, granting their organisation read access to events belonging to other organisations. If the target organisation accepts the delegation, event ownership can be transferred and the original delegation record deleted.

3

Are default deployments affected?

The issue requires delegation to be enabled through the MISP.delegation server setting. The provided information does not state whether that setting is enabled by default.

4

What can be done if upgrading is not immediately possible?

Disable the MISP.delegation server setting where operationally feasible, and restrict perm_delegate to only trusted users. These actions remove or limit the stated exploitation prerequisites.

5

How can administrators identify potentially affected systems?

Systems running MISP versions earlier than 2.5.48 are affected if MISP.delegation is enabled. Review delegation records and accepted delegations for unexpected event_id changes, retargeted records, or event ownership transfers involving unrelated organisations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203