CVE-2026-103239: MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection

Published Sep 30, 2026
·
Updated

MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.

A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.

Preconditions:

- An authenticated account with the tag editor permission (permtageditor)

- Network access to the MISP instance

Impact:

- Unauthorized creation or modification of User and Organisation records

- Privilege escalation from tag editor to site administrator

Affected versions: < 2.5.48

Affected Software

1 affected component
Misp Misp<2.5.48

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MISP to a version that resolves this vulnerability.

    Fixed in 2.5.48

Event History

Sep 30, 2026
CVE Published
via MITRE·10:16 AM
Data Sourced
via MITRE·10:16 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An attacker needs network access to the MISP instance and an authenticated account with the tag editor permission (perm_tag_editor). Unauthenticated users and authenticated users without that permission are not described as able to exploit it.

2

What does an attacker need to send to trigger the issue?

The attacker must craft a tag collection creation or editing request containing additional associated-model data, such as User or Organisation records, alongside the expected tag collection fields. The vulnerable bulk-association save operation processes those injected sibling records.

3

What is the practical impact of successful exploitation?

A tag editor can create or modify User and Organisation records without authorization. This can allow privilege escalation from the tag editor role to site administrator.

4

Which MISP versions are affected?

MISP versions earlier than 2.5.48 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203