CVE-2026-10868: MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification

Published Jun 4, 2026
·
Updated

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craft a modified request containing another user identifier, potentially causing updates to be applied to an unintended user account. Depending on the editable fields and the attacker’s privileges, this could allow unauthorized modification of user account attributes and impact account integrity.

The issue was addressed by explicitly removing the User.id field from request data before processing the user edit operation.

Affected Software

1 affected component
Misp Project Misp

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In UsersController::edit(), explicitly unset/remove the 'User.id' field from the incoming request data before applying user edits, so the server does not accept a user-controlled User.id from the request.

    MISP (UsersController::edit()) Request data filtering for user edit = Remove User.id from request data before processing edit operation

Event History

Jun 4, 2026
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10868?

CVE-2026-10868 has a risk rating of 47.

2

How do I fix CVE-2026-10868?

To fix CVE-2026-10868, ensure proper validation and filtering of user-supplied fields in the UsersController::edit() method.

3

What application is affected by CVE-2026-10868?

CVE-2026-10868 affects the MISP Project (MISP) application.

4

Can an attacker exploit CVE-2026-10868 without authentication?

No, an attacker needs to be authenticated to exploit CVE-2026-10868.

5

What type of vulnerability is CVE-2026-10868?

CVE-2026-10868 is a mass assignment vulnerability that allows unauthorized user account modification.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203