PULSE
FEED
ransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomnetrunner reclama a P***** M***** I** · Not Foundransomemperador reclama a SitePro Rentals · Otherransomsafepay reclama a econ-tec.com · DE · Technologyransomsafepay reclama a assist2enjoy.be · BE · Otherransomlamashtu reclama a Dr Damiel Pugliese · Healthcareransomlamashtu reclama a Astidental di Sabbione · IT · Manufacturingransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Services
← Todos los CVEs
CVE Watch30 sept 2026

CVE-2026-103235

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation r

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-639 · CWE-915

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id. An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted. Preconditions: - An authenticated user with the delegation permission (perm_delegate) - The MISP.delegation server setting must be enabled Impact: - Confidentiality: read access to any event on the instance - Integrity: overwriting existing delegation records and transferring event ownership Affected versions: MISP < 2.5.48

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-972825.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.5h
CVE-2026-970794.3 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.5h
CVE-2026-970785.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.5h
CVE-2026-970744.3 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.5h
CVE-2026-970665.3 MED
—
———Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.5h
CVE-2026-963476.5 MED
—
———Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.5h