{"api_version":"1","generated_at":"2026-10-01T04:01:54+00:00","cve":"CVE-2026-103235","urls":{"html":"https://cve.report/CVE-2026-103235","api":"https://cve.report/api/cve/CVE-2026-103235.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-103235","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-103235"},"summary":{"title":"MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events","description":"MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP < 2.5.48","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-09-30 10:17:16","updated_at":"2026-09-30 15:22:26"},"problem_types":["CWE-639","CWE-915","CWE-915 CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes","CWE-639 CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/MISP/commit/d1f5684f9","name":"https://github.com/MISP/MISP/commit/d1f5684f9","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-103235","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103235","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"MISP","version":"affected 2.5.48 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jeroen Pinoy","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 5","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-103235","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-30T14:32:35.584208Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-30T14:32:45.581Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","modules":["EventDelegationsController"],"product":"MISP","programFiles":["app/Controller/EventDelegationsController.php"],"repo":"https://github.com/MISP/MISP","vendor":"MISP","versions":[{"lessThan":"2.5.48","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.</p><p>An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.</p><p>Preconditions:</p><p>- An authenticated user with the delegation permission (perm_delegate)</p><p>- The MISP.delegation server setting must be enabled</p><p>Impact:</p><p>- Confidentiality: read access to any event on the instance</p><p>- Integrity: overwriting existing delegation records and transferring event ownership</p><p>Affected versions: MISP &lt; 2.5.48</p>"}],"value":"MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP < 2.5.48"}],"impacts":[{"capecId":"CAPEC-12","descriptions":[{"lang":"en","value":"CAPEC-12 Mass Assignment"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-915","description":"CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-639","description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T09:12:56.533Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/MISP/commit/d1f5684f9"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.</p>"}],"value":"The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records."}],"source":{"discovery":"UNKNOWN"},"title":"MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"full","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.","PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.","VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.","The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.","The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption."],"capecRationale":[{"capecId":"CAPEC-12","rationale":"The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence."}],"commit":"d1f5684f9a193ea0a8a4f7709703011aa69d9682","confidence":"high","credits":[{"lang":"en","type":"reporter","value":"Jeroen Pinoy"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 5"}],"cvssRationale":"Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.","fixSummary":"The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.","generatedAt":"2026-09-30T07:37:05.841152Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":9,"assumptionCount":5,"confidence":"high","model":"qwen3.8:27b","score":6}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611","patchSummary":"In EventDelegationsController::delegateEvent(), the code previously saved $this->request->data['EventDelegation'] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.","patchTruncated":false,"patches":[{"commit":"d1f5684f9a193ea0a8a4f7709703011aa69d9682","patchSha256":"f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611","source":"https://github.com/MISP/MISP/commit/d1f5684f9.patch","sourceUrl":"https://github.com/MISP/MISP/commit/d1f5684f9.patch","subject":"fix: [security] Delegation requests stay bound to the event"}],"source":"https://github.com/MISP/MISP/commit/d1f5684f9.patch","subject":"fix: [security] Delegation requests stay bound to the event","tagVersionBoundary":{"commits_after_fix":22,"repository":"https://github.com/MISP/MISP","tag":"v2.5.48","version":"2.5.48","version_type":"semver"},"weaknessRationale":[{"cweId":"CWE-915","rationale":"The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation."},{"cweId":"CWE-639","rationale":"The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary."}]}}},"recordType":"advisory","vulnId":"GCVE-1-2026-20227"}],"x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-103235","datePublished":"2026-09-30T09:09:36.761Z","dateReserved":"2026-09-30T09:09:33.466Z","dateUpdated":"2026-09-30T14:32:45.581Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 10:17:16","lastModifiedDate":"2026-09-30 15:22:26","problem_types":["CWE-639","CWE-915","CWE-915 CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes","CWE-639 CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T14:32:35.584208Z","id":"CVE-2026-103235","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"103235","Ordinal":"1","Title":"MISP Event Delegation Mass Assignment Allows Retargeting Delegat","CVE":"CVE-2026-103235","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"103235","Ordinal":"1","NoteData":"MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP < 2.5.48","Type":"Description","Title":"MISP Event Delegation Mass Assignment Allows Retargeting Delegat"}]}}}