OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103239

HIGH · CVSS 8.6 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

MISP is vulnerable to a privilege escalation flaw in its tag collection creation and editing functionality, allowing authenticated users with tag editor permissions to inject additional model data into the database. This vulnerability enables attackers to create or modify User and Organisation records, potentially escalating their privileges to that of a site administrator. Organizations utilizing MISP versions prior to 2.5.48 should prioritize patching this vulnerability to mitigate the risk of unauthorized access and data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103239
Severity
HIGH
CVSS
8.6
EPSS
0.26%

Original NVD Description

MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48