A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.
Preconditions:
- An authenticated account with the tag editor permission (perm_tag_editor)
- Network access to the MISP instance
Impact:
- Unauthorized creation or modification of User and Organisation records
- Privilege escalation from tag editor to site administrator
Affected versions: < 2.5.48
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The fix replaces the bulk-association save call with an explicit two-step process: first, only the TagCollection data is extracted from the request and saved via a plain save() operation that does not write belongsTo siblings; second, tag association rows are persisted individually in a controlled loop. This ensures that any User, Organisation, or other sibling model data present in the request payload is silently discarded and never reaches the database, eliminating the privilege escalation path.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/96f735e7b |
|
Wed, 30 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48 | |
| Title | MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-284 CWE-862 |
|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-09-30T10:16:18.835Z
Reserved: 2026-09-30T10:16:15.941Z
Link: CVE-2026-103239
No data.
Status : Deferred
Published: 2026-09-30T11:16:43.527
Modified: 2026-09-30T11:16:43.637
Link: CVE-2026-103239
No data.
OpenCVE Enrichment
Updated: 2026-09-30T12:00:16Z