CVE-2026-103237: MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows

Published Sep 30, 2026
·
Updated

MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the eventid or objectid to the caller's context. However, the underlying ORM's set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.

An authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, eventid pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and eventid. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.

Impact:

- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)

- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute

- Requires only a low-privilege authenticated account with permadd

Affected versions: <2.5.48

Affected Software

1 affected component
Misp Misp<2.5.48

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in 2.5.48

Event History

Sep 30, 2026
CVE Published
via MITRE·09:56 AM
Data Sourced
via MITRE·09:56 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need?

An attacker must be authenticated and have basic write permissions. No access to the victim organization’s or event’s rows is required for the described cross-tenant modification.

2

Which application workflows are exposed to this input pattern?

The affected save path is used by attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, and user admin edit.

3

What can an attacker do to records outside their authorized context?

They can supply an attacker-chosen row ID and event ID through a nested model-alias block, allowing rows to be overwritten, re-parented to attacker events, or soft-deleted. This can affect data belonging to organizations or events the attacker cannot read.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203