CVE-2026-103235: MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events
MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and eventid.
An authenticated attacker could inject a primary key or eventid into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.
Preconditions:
- An authenticated user with the delegation permission (permdelegate)
- The MISP.delegation server setting must be enabled
Impact:
- Confidentiality: read access to any event on the instance
- Integrity: overwriting existing delegation records and transferring event ownership
Affected versions: MISP < 2.5.48
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MISPto a version that resolves this vulnerability.Fixed in 2.5.48
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated, have the perm_delegate permission, and be able to use an instance where the MISP.delegation setting is enabled. Users without that permission do not meet the stated preconditions.
What access could exploitation provide?
The attacker can retarget a delegation record to arbitrary events on the instance, granting their organisation read access to events belonging to other organisations. If the target organisation accepts the delegation, event ownership can be transferred and the original delegation record deleted.
Are default deployments affected?
The issue requires delegation to be enabled through the MISP.delegation server setting. The provided information does not state whether that setting is enabled by default.
What can be done if upgrading is not immediately possible?
Disable the MISP.delegation server setting where operationally feasible, and restrict perm_delegate to only trusted users. These actions remove or limit the stated exploitation prerequisites.
How can administrators identify potentially affected systems?
Systems running MISP versions earlier than 2.5.48 are affected if MISP.delegation is enabled. Review delegation records and accepted delegations for unexpected event_id changes, retargeted records, or event ownership transfers involving unrelated organisations.