PT-2026-48973 · Misp · Misp
Andras Iklody
+1
·
Published
2026-06-12
·
Updated
2026-06-12
·
CVE-2026-54361
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
Multiple mass assignment issues exist in the handling of collections, tag collections, event delegations, and shadow attributes. Certain controller actions accept user-supplied fields that should be server-controlled, specifically record identifiers and ownership fields such as
id, org id, orgc id, and user id. An authenticated attacker can craft requests to these endpoints to alter object ownership, redirect updates to different records, overwrite event delegation requests, or modify shadow attribute proposals of other organizations. This may lead to unauthorized modification of objects and potential unauthorized access to or transfer of sensitive threat intelligence data. The affected functions include CollectionsController::edit(), EventDelegationsController::delegateEvent(), ShadowAttributesController::edit(), TagCollectionsController::edit(), and TagCollectionsController::editWithTags().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp