PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-103239

MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted t

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-284 · CWE-862

EPSS · 30d

Not enough EPSS history yet.

Technical description

MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload. A user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator. Preconditions: - An authenticated account with the tag editor permission (perm_tag_editor) - Network access to the MISP instance Impact: - Unauthorized creation or modification of User and Organisation records - Privilege escalation from tag editor to site administrator Affected versions: < 2.5.48

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972855.4 MED
—
———Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.7h
CVE-2026-972674.3 MED
—
———Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.7h
CVE-2026-972476.5 MED
—
———Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.7h
CVE-2026-972435.4 MED
—
———Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.7h
CVE-2026-972396.5 MED
—
———Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.7h
CVE-2026-971977.5 HIG
—
———Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.7h