CVE-2026-103239 Overview
CVE-2026-103239 is a privilege escalation vulnerability in MISP, the open-source threat intelligence sharing platform. The flaw exists in the tag collection creation and editing functionality, where affected controller actions accept the full HTTP request payload and pass it to a bulk-association save operation. Because the save operation processes all associated model data indiscriminately, an authenticated user with the perm_tag_editor permission can inject sibling records for User or Organisation models. This allows the attacker to create or modify privileged accounts and escalate to site administrator. The issue is tracked under CWE-284: Improper Access Control and affects MISP versions prior to 2.5.48.
Critical Impact
A low-privileged tag editor account can escalate to full site administrator by injecting User or Organisation records into tag collection save requests.
Affected Products
- MISP versions prior to 2.5.48
- MISP tag collection creation and editing controller actions
- Deployments exposing MISP to any authenticated user with perm_tag_editor
Discovery Timeline
- 2026-09-30 - CVE-2026-103239 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-103239
Vulnerability Analysis
MISP's tag collection controller actions handle POST requests that create or edit tag collections. Rather than filtering the request payload to only fields relevant to the TagCollection model, the handler forwards the entire request body to a CakePHP bulk-association save operation. CakePHP's saveAssociated style persistence writes any related model data present in the payload alongside the primary record.
An attacker with the tag editor permission crafts a request that mixes legitimate tag collection fields with additional keys naming other models such as User or Organisation. The save operation persists those sibling records without checking whether the caller is authorized to modify them. The result is unauthorized creation or modification of accounts, including elevation to site_admin role.
Root Cause
The root cause is improper access control at the persistence layer. The controller does not enforce a model-level allowlist or field-level whitelist before invoking the bulk save. Authorization for the tag collection action does not extend to the sibling models the same call writes.
Attack Vector
Exploitation requires an authenticated MISP account with perm_tag_editor and network reachability to the MISP instance. The attacker submits a crafted HTTP POST to the tag collection create or edit endpoint containing extra associated-model payload keys. The server writes the injected User or Organisation records during the tag collection save. See the MISP fix commit 96f735e7b for the exact controller and model changes.
No public proof-of-concept code is available. The vulnerability mechanism is documented in the vendor commit referenced above.
Detection Methods for CVE-2026-103239
Indicators of Compromise
- Unexpected User records with role_id corresponding to site administrator created shortly after tag collection POST requests.
- Modifications to Organisation records with no corresponding admin-initiated audit entry.
- Audit log entries showing tag collection create or edit actions performed by accounts that subsequently gained elevated privileges.
Detection Strategies
- Review MISP audit logs for tag collection create and edit actions correlated with user or organisation table changes in the same request window.
- Compare the current administrator account list against a known-good baseline and alert on additions or role changes.
- Inspect web server access logs for POST requests to /tag_collections/add and /tag_collections/edit with abnormally large request bodies.
Monitoring Recommendations
- Enable database-level auditing on the users and organisations tables and alert on writes originating from the MISP application account outside expected admin workflows.
- Alert on any new account assigned the site_admin role and require out-of-band confirmation.
- Forward MISP application and web server logs to a centralized log platform for correlation and retention.
How to Mitigate CVE-2026-103239
Immediate Actions Required
- Upgrade MISP to version 2.5.48 or later, which restricts the tag collection save operation to the intended model fields.
- Audit all user accounts and organisation records created or modified since the vulnerable version was deployed.
- Revoke perm_tag_editor from accounts that do not strictly require it until patching completes.
Patch Information
The upstream fix is available in the MISP repository. Review the MISP commit 96f735e7b for the exact code changes. Deploy MISP 2.5.48 or newer following the project's standard upgrade procedure, then restart the application and worker processes.
Workarounds
- Temporarily remove the perm_tag_editor permission from all non-administrator roles until the patch is applied.
- Place the MISP instance behind a reverse proxy or WAF rule that blocks POST bodies to /tag_collections/add and /tag_collections/edit containing keys named User or Organisation.
- Restrict network access to the MISP web interface to trusted analyst networks or VPN clients.
# Example WAF rule fragment (ModSecurity) to block sibling model injection
SecRule REQUEST_URI "@rx ^/tag_collections/(add|edit)" \
"id:1039239,phase:2,deny,status:403,\
chain,msg:'CVE-2026-103239 tag collection sibling model injection'"
SecRule ARGS_NAMES "@rx ^(User|Organisation)(\[|\.)" "t:none"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
