PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-103235

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation r

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-639 · CWE-915

EPSS · 30d

Not enough EPSS history yet.

Technical description

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972825.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.5h
CVE-2026-970794.3 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.5h
CVE-2026-970785.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.5h
CVE-2026-970744.3 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.5h
CVE-2026-970665.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.5h
CVE-2026-963476.5 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.5h