PT-2026-48973 · Misp · Misp

Andras Iklody

+1

·

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-54361

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description Multiple mass assignment issues exist in the handling of collections, tag collections, event delegations, and shadow attributes. Certain controller actions accept user-supplied fields that should be server-controlled, specifically record identifiers and ownership fields such as id, org id, orgc id, and user id. An authenticated attacker can craft requests to these endpoints to alter object ownership, redirect updates to different records, overwrite event delegation requests, or modify shadow attribute proposals of other organizations. This may lead to unauthorized modification of objects and potential unauthorized access to or transfer of sensitive threat intelligence data. The affected functions include CollectionsController::edit(), EventDelegationsController::delegateEvent(), ShadowAttributesController::edit(), TagCollectionsController::edit(), and TagCollectionsController::editWithTags().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-54361

Affected Products

Misp