CVE-2026-103237 Overview
CVE-2026-103237 is an improper input validation vulnerability [CWE-20] in the Malware Information Sharing Platform (MISP) ORM save path. The flaw affects MISP versions prior to 2.5.48 and impacts multiple entity types including Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute. An authenticated user with basic perm_add write permissions can overwrite, re-parent, or soft-delete records belonging to other organizations or events they cannot read. Exploitation requires embedding a nested block under the model alias key inside a request payload to bypass sanitization applied to the outer record.
Critical Impact
Low-privileged authenticated users can compromise cross-tenant data integrity by rewriting attributes, re-parenting objects to attacker-controlled events, or soft-deleting rows in events they have no read access to.
Affected Products
- MISP (Malware Information Sharing Platform) versions prior to 2.5.48
- MISP Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute entity handlers
- MISP endpoints for attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, and user admin edit
Discovery Timeline
- 2026-09-30 - CVE-2026-103237 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-103237
Vulnerability Analysis
The vulnerability resides in how MISP controllers hand off client-supplied data to the CakePHP ORM set() method. Controllers sanitize the flat request record by stripping the primary key id and pinning event_id or object_id to the caller's context. This sanitization enforces tenant isolation and prevents cross-event modification.
The ORM set() method, however, prefers a nested key whose name matches the model alias over sibling scalar fields. When the request payload contains both a flat scalar block and a nested block keyed by the model alias, the ORM binds to the inner block and discards the sanitized outer fields. The attacker-controlled id and event_id inside the nested block are used verbatim during the save operation.
The result is a save-path authorization bypass that affects every controller path relying on the flat-record sanitization pattern. This includes attribute editing, event report creation, sighting capture, and shadow attribute proposals across the Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute models.
Root Cause
The root cause is a mismatch between controller-level input validation and ORM-level data binding semantics. Sanitization operates on the outer scalar keys, while the ORM binds to a nested alias-keyed block when present. The controllers never normalize the request shape before applying the sanitization, so the enforced constraints on id and event_id are silently discarded.
Attack Vector
An authenticated user with perm_add submits a POST or PUT request to a vulnerable endpoint such as attribute edit or event report creation. The payload contains a nested block under the model alias key with attacker-chosen id and event_id values referencing rows in other organizations. The ORM saves against those attacker-supplied identifiers, allowing cross-tenant overwrite, re-parenting, or soft-deletion.
// Patch: app/Controller/AttributesController.php
// The controller now wraps the entire request payload under the model alias,
// ensuring sanitization applies to the same record the ORM binds to.
// check each of them and return a json object with the successful deletes and the failed ones.
if ($this->_isRest()) {
if (empty($this->request->data['Attribute'])) {
- $this->request->data['Attribute'] = $this->request->data;
+ $this->request->data = array('Attribute' => $this->request->data);
}
if (isset($this->request->data['Attribute']['id'])) {
$ids = $this->request->data['Attribute']['id'];
Source: MISP commit 9485ae40d
// Patch: app/Controller/EventReportsController.php
// Same normalization pattern applied to the EventReport controller.
$event = $this->__canModifyReport($eventId);
if ($this->request->is('post') || $this->request->is('put')) {
if (!isset($this->request->data['EventReport'])) {
- $this->request->data['EventReport'] = $this->request->data;
+ $this->request->data = array('EventReport' => $this->request->data);
}
$report = $this->request->data;
$errors = $this->EventReport->addReport($this->Auth->user(), $report, $eventId);
Source: MISP commit 9485ae40d
Detection Methods for CVE-2026-103237
Indicators of Compromise
- Request bodies to attribute, event report, sighting, or shadow attribute endpoints containing a nested key matching the model alias (for example Attribute, EventReport, Sighting, ShadowAttribute) alongside outer scalar fields.
- Audit log entries showing modifications to attributes or objects belonging to organizations or events the authenticated user is not a member of.
- Unexpected changes to event_id or object_id fields on existing rows, indicating re-parenting activity.
- Soft-deleted attributes or objects with no corresponding legitimate user action in the audit trail.
Detection Strategies
- Parse MISP HTTP request logs for POST or PUT payloads that contain both a nested model alias block and an id field inside that block.
- Correlate MISP audit logs against user organization membership to identify save operations that cross tenant boundaries.
- Baseline normal API usage patterns per user and alert on sudden write activity targeting events outside the user's organization.
Monitoring Recommendations
- Enable and forward MISP audit logs to a central log platform and retain them for post-incident forensics.
- Monitor the ratio of write operations per user against the events they own or belong to as a member.
- Track counts of perm_add accounts and review privilege assignments regularly.
How to Mitigate CVE-2026-103237
Immediate Actions Required
- Upgrade MISP to version 2.5.48 or later, which contains the request normalization fix in the affected controllers.
- Audit perm_add account membership and revoke the permission from accounts that do not require write access.
- Review recent modifications, re-parenting, and soft-delete events across Attribute, Object, EventReport, Sighting, AttributeTag, and ShadowAttribute records for signs of abuse.
Patch Information
The fix is delivered in MISP commit 9485ae40d. Controllers now wrap the entire incoming request under the model alias key before sanitization, ensuring the sanitized outer record and the ORM-bound inner record are the same object. Details are available in the MISP security commit.
Workarounds
- Restrict perm_add to trusted accounts until the patched version is deployed.
- Place MISP behind a reverse proxy or web application firewall configured to reject request bodies containing nested keys matching MISP model aliases such as Attribute, EventReport, Sighting, and ShadowAttribute.
- Increase audit log verbosity and review write operations frequently until upgrade is complete.
# Upgrade MISP to the patched release
cd /var/www/MISP
sudo -u www-data git fetch origin
sudo -u www-data git checkout v2.5.48
sudo -u www-data git submodule update --init --recursive
sudo systemctl restart apache2
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
