However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.
Impact:
- A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.
- A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.
- A user could reassign a model's organisation to an arbitrary value.
Preconditions:
- Authenticated user with decaying-model permission (perm_decaying).
- Network access to the MISP instance.
Affected: <2.5.48.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/MISP/MISP/commit/70e319e4b |
|
Fri, 02 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected: <2.5.48. | |
| Title | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging | |
| First Time appeared |
Misp
Misp misp |
|
| Weaknesses | CWE-285 CWE-915 |
|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Misp
Misp misp |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-10-02T16:19:17.687Z
Reserved: 2026-10-02T15:56:12.330Z
Link: CVE-2026-104908
Updated: 2026-10-02T16:19:08.415Z
Status : Deferred
Published: 2026-10-02T16:16:48.580
Modified: 2026-10-02T17:17:05.017
Link: CVE-2026-104908
No data.
OpenCVE Enrichment
Updated: 2026-10-02T17:45:17Z