Description
MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off.

However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.

Impact:

- A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.

- A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.

- A user could reassign a model's organisation to an arbitrary value.

Preconditions:

- Authenticated user with decaying-model permission (perm_decaying).

- Network access to the MISP instance.

Affected: <2.5.48.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The import handler now builds the model record from an explicit allow-list of permitted fields (name, parameters, description, ref, formula, version, enabled, all_orgs) using array_intersect_key, discarding any unlisted keys including nested model objects. The organisation identifier and default flag are set unconditionally after filtering. The save operation is preceded by an explicit create() call and the data is wrapped in the proper model key, preventing the ORM from interpreting attacker-supplied nested keys as separate model attributes.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected: <2.5.48.
Title MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging
First Time appeared Misp
Misp misp
Weaknesses CWE-285
CWE-915
CPEs cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Vendors & Products Misp
Misp misp
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-10-02T16:19:17.687Z

Reserved: 2026-10-02T15:56:12.330Z

Link: CVE-2026-104908

cve-icon Vulnrichment

Updated: 2026-10-02T16:19:08.415Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:48.580

Modified: 2026-10-02T17:17:05.017

Link: CVE-2026-104908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:45:17Z

Weaknesses