天下漏洞,尽知其名
HIGH

CVE-2026-103235 MISP 事件委托功能批量赋值漏洞

影响攻击者可越权读取任意事件,甚至转移事件所有权

AI 研判

MISP 的事件委托功能存在批量赋值漏洞。应用仅对 URL 中指定的事件校验用户权限,却将用户提交的整条记录(含主键、event_id 等字段)直接持久化。攻击者可借此把已有委托记录重定向到任意事件,从而获得跨组织的读取权限。

影响范围

MISP

MISP 2.5.48 之前的版本受影响,官方公告给出的范围为 MISP < 2.5.48。

漏洞详情

漏洞类型为批量赋值(Mass Assignment)。成因是服务端在保存委托请求时未对客户端可控字段做白名单过滤,允许覆盖主键与 event_id。利用方式是已认证且具备 perm_delegate 权限的用户提交特制委托请求,将委托记录指向目标事件,从而读取该事件;若目标组织接受委托,事件所有权还会被转移且原记录被删除。

利用条件与风险

利用前提是攻击者拥有已认证账户及委托权限(perm_delegate),且服务端启用了 MISP.delegation 设置。实战中可造成跨组织敏感事件信息泄露,并可能篡改或转移事件归属,风险较高。

修复建议

建议升级至 MISP 2.5.48 或更高版本。临时缓解措施包括:关闭 MISP.delegation 服务端设置,或严格限制具备 perm_delegate 权限的账户范围;具体修复细节以官方公告为准。

原始情报

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.

An authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.

Preconditions:

– An authenticated user with the delegation permission (perm_delegate)

– The MISP.delegation server setting must be enabled

Impact:

– Confidentiality: read access to any event on the instance

– Integrity: overwriting existing delegation records and transferring event ownership

Affected versions: MISP < 2.5.48