Action not permitted
Modal body text goes here.
Modal Title
Modal Body
WID-SEC-W-2026-3705
Vulnerability from csaf_certbund - Published: 2026-10-01 22:00 - Updated: 2026-10-01 22:00| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Open Source MISP <2.5.48
Open Source / MISP
|
<2.5.48 |
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "MISP ist eine Open-Source-Plattform f\u00fcr den Informationsaustausch \u00fcber Bedrohungen.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in MISP ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuf\u00fchren, Daten offenzulegen und zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuf\u00fchren.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Linux\n- MacOS X\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3705 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3705.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3705 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3705"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-28MQ-63WC-4252"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-2HXJ-RRWR-5G5V"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-R4V7-FGM4-552C"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-P9M5-XWGX-8J69"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-66PP-JMHC-R9MV"
},
{
"category": "external",
"summary": "GitHub Advisory Database vom 2026-10-01",
"url": "https://github.com/advisories/GHSA-VWHJ-WMRX-P88C"
}
],
"source_lang": "en-US",
"title": "MISP: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-10-01T22:00:00.000+00:00",
"generator": {
"date": "2026-10-02T10:26:51.993+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3705",
"initial_release_date": "2026-10-01T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-10-01T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c2.5.48",
"product": {
"name": "Open Source MISP \u003c2.5.48",
"product_id": "T060583"
}
},
{
"category": "product_version",
"name": "2.5.48",
"product": {
"name": "Open Source MISP 2.5.48",
"product_id": "T060583-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:misp:misp:2.5.48"
}
}
}
],
"category": "product_name",
"name": "MISP"
}
],
"category": "vendor",
"name": "Open Source"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-103651",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103651"
},
{
"cve": "CVE-2026-103655",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103655"
},
{
"cve": "CVE-2026-103659",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103659"
},
{
"cve": "CVE-2026-103662",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103662"
},
{
"cve": "CVE-2026-103664",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103664"
},
{
"cve": "CVE-2026-103858",
"product_status": {
"known_affected": [
"T060583"
]
},
"release_date": "2026-10-01T22:00:00.000+00:00",
"title": "CVE-2026-103858"
}
]
}
CVE-2026-103651 (GCVE-0-2026-103651)
Vulnerability from cvelistv5 – Published: 2026-10-01 07:34 – Updated: 2026-10-01 15:32| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/f34aee2c7 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 07:22 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/f34aee2c7.patch
9ec05e4a3d95… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
f34aee2c74e1
|
fix: [security] Burn paper OTP tokens against the stored | 9ec05e4a3d95… |
Fix summary
The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.
Patch summary
In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user['hotp_counter']) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user's totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.
CVSS rationale
AV:N – MISP is a network-accessible web application. AC:H – exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N – no manipulation of the target system is needed. PR:L – the attacker must be an authenticated user with a pending OTP session. UI:N – no additional user interaction is required beyond the initial login flow. VC:H – successful exploitation grants full access to the target user's MISP account and its data. VI:H – the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N – no denial-of-service impact is evident. SC/SI/SA:N – no secondary system impact is indicated by the patch.
Weakness rationale
- CWE-362 The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value.
- CWE-287 The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check.
Attack pattern rationale
- CAPEC-111 The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match.
Assumptions to verify
- The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.
- The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.
- CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.
- The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.
- The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/f34aee2c7.patch"
],
"timestamp": "2026-09-23T14:20:38Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103651",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:31:56.170497Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:32:08.372Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Controller/UsersController.php"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\u003c/p\u003e\u003cp\u003eThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has HOTP (paper token) second-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\u003c/p\u003e\u003cp\u003e- The attacker has access to at least one HOTP token value (e.g., a paper token list).\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\u003c/p\u003e\u003cp\u003e- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\n\nThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\n\nPreconditions:\n\n- The target user has HOTP (paper token) second-factor authentication enabled.\n\n- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\n\n- The attacker has access to at least one HOTP token value (e.g., a paper token list).\n\nSecurity impact:\n\n- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\n\n- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-111",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-111 Race Condition"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:22:27Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-362",
"description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "CWE-287 Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T07:34:02.597Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/f34aee2c7"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.\u003c/p\u003e"
}
],
"value": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused."
}
],
"title": "MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.",
"The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.",
"CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.",
"The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.",
"The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-111",
"rationale": "The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match."
}
],
"commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N \u2013 MISP is a network-accessible web application. AC:H \u2013 exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N \u2013 no manipulation of the target system is needed. PR:L \u2013 the attacker must be an authenticated user with a pending OTP session. UI:N \u2013 no additional user interaction is required beyond the initial login flow. VC:H \u2013 successful exploitation grants full access to the target user\u0027s MISP account and its data. VI:H \u2013 the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N \u2013 no denial-of-service impact is evident. SC/SI/SA:N \u2013 no secondary system impact is indicated by the patch.",
"fixSummary": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.",
"generatedAt": "2026-10-01T07:22:27.568266Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
"patchSummary": "In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user[\u0027hotp_counter\u0027]) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user\u0027s totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.",
"patchTruncated": false,
"patches": [
{
"commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
"date": "Wed, 23 Sep 2026 16:20:38 +0200",
"patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
"source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"subject": "fix: [security] Burn paper OTP tokens against the stored"
}
],
"source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:22:27Z",
"version": "2.0.3"
},
"subject": "fix: [security] Burn paper OTP tokens against the stored",
"tagVersionBoundary": {
"commits_after_fix": 41,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-362",
"rationale": "The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value."
},
{
"cweId": "CWE-287",
"rationale": "The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/f34aee2c7.patch"
],
"timestamp": "2026-09-23T14:20:38Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20307"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103651",
"datePublished": "2026-10-01T07:34:02.597Z",
"dateReserved": "2026-10-01T07:34:00.794Z",
"dateUpdated": "2026-10-01T15:32:08.372Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103655 (GCVE-0-2026-103655)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:08 – Updated: 2026-10-01 15:25- CWE-294 - Authentication Bypass via Logical Flaw
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/a020fa47b | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 07:52 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/a020fa47b.patch
6fce2d1f789e… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
a020fa47b6c3
|
fix: [security] Refuse a TOTP code that was already used to | 6fce2d1f789e… |
Fix summary
The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.
Patch summary
In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.
CVSS rationale
AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim's normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user's account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.
Weakness rationale
- CWE-294 The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287.
Attack pattern rationale
- CAPEC-122 The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user's authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match.
Assumptions to verify
- The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.
- The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.
- The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.
- CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.
- The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix's behavior is not specified in the patch.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/a020fa47b.patch"
],
"timestamp": "2026-09-23T14:24:44Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103655",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:25:45.460434Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:25:55.269Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"app/Controller/UsersController.php (otp method)"
],
"product": "MISP",
"programFiles": [
"app/Controller/UsersController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\u003c/p\u003e\u003cp\u003eThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has TOTP-based two-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\u003c/p\u003e\u003cp\u003e- The replay must occur within the TOTP validity period.\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Unauthorized account access by replaying a captured one-time code.\u003c/p\u003e\u003cp\u003e- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;v2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window.\n\nThe issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user\u0027s login could replay it to authenticate a second session as that user.\n\nPreconditions:\n\n- The target user has TOTP-based two-factor authentication enabled.\n\n- The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client).\n\n- The replay must occur within the TOTP validity period.\n\nSecurity impact:\n\n- Unauthorized account access by replaying a captured one-time code.\n\n- Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user.\n\nAffected versions: \u003cv2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Session Hijacking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:43Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-294",
"description": "CWE-294 Authentication Bypass via Logical Flaw",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:08:55.013Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/a020fa47b"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.\u003c/p\u003e"
}
],
"value": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window."
}
],
"title": "MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is inferred from the tag_version_boundary (v2.5.48, 40 commits after fix); the exact first affected version is not stated in the patch metadata and is recorded as unspecified.",
"The TOTP validity period is assumed to be the standard 30 seconds based on the OTPHP library default; the patch does not hard-code a specific period value.",
"The CAPEC-122 mapping is the closest available pattern; no CAPEC specifically addresses one-time-code replay, so the mapping carries uncertainty.",
"CVSS AC is rated High because exploitation requires intercepting a valid TOTP code during a live login and replaying it within a short time window; if the attacker already possesses the code (e.g., via a compromised client), complexity would be lower.",
"The Redis dependency for the fix is assumed to be available in the deployment; if Redis is unavailable, the fix\u0027s behavior is not specified in the patch.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); it is credited as a tool rather than a human remediation developer."
],
"capecRationale": [
{
"capecId": "CAPEC-122",
"rationale": "The closest available CAPEC pattern is Session Hijacking, as the attacker gains unauthorized access to a user\u0027s authenticated session by replaying a captured credential (the TOTP code). The mapping is imperfect because the attack targets a one-time authentication token rather than a persistent session identifier, and the window is very short (one TOTP period). No CAPEC specifically covers one-time-code replay, so CAPEC-122 is the best available match."
}
],
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Tanguy Snoeck of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: the TOTP code is transmitted over the network during login. AC:H: exploitation requires the attacker to intercept a valid TOTP code during a legitimate login and replay it within the short validity window (typically 30 s), which is a non-trivial timing and positioning requirement. AT:N: no manipulation of the target system is needed. PR:N: the attacker is unauthenticated. UI:N: no user interaction beyond the victim\u0027s normal login is required. VC:H / VI:H: successful exploitation grants full access to the targeted user\u0027s account, including threat-intelligence data and administrative capabilities. VA:L: the attacker could disrupt services by modifying or deleting data. SC/SI/SA:N: no impact on secondary systems is evidenced.",
"fixSummary": "The fix introduces a single-use enforcement mechanism for TOTP codes. Upon successful verification, the system records the TOTP period step in a Redis key scoped to the user and step number, using a SET-NX (set-if-not-exists) operation with a TTL of three times the TOTP period. Any subsequent attempt to authenticate with a code from the same period will fail the SET-NX check and be rejected, effectively making each TOTP code single-use within its validity window.",
"generatedAt": "2026-10-01T07:52:44.000034Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"patchSummary": "In app/Controller/UsersController.php, the otp() method was modified to capture the current timestamp and pass it to the TOTP verify call. A new private method __claimTotpStep() was added, which computes the TOTP step (intdiv of elapsed time over period), constructs a Redis key of the form misp:otp:totp_used:{userId}:{step}, and attempts a SET with NX and EX (3x period) flags via RedisTool. The login proceeds only if both the TOTP verification and the claim succeed. Thirteen lines added, one line modified.",
"patchTruncated": false,
"patches": [
{
"commit": "a020fa47b6c3cb5b43d841afe2ccf149889fad6b",
"date": "Wed, 23 Sep 2026 16:24:44 +0200",
"patchSha256": "6fce2d1f789e3b4c0cbb7b4d81079334f66f1707bb5422f49915393cab88143f",
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"subject": "fix: [security] Refuse a TOTP code that was already used to"
}
],
"source": "https://github.com/MISP/MISP/commit/a020fa47b.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T07:52:44Z",
"version": "2.0.3"
},
"subject": "fix: [security] Refuse a TOTP code that was already used to",
"tagVersionBoundary": {
"commits_after_fix": 40,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-294",
"rationale": "The TOTP verification logic accepted the same code multiple times within its validity period because no state was tracked to mark a period as consumed. This is a logical flaw in the authentication mechanism that permits replay of a valid one-time credential, fitting CWE-294 more precisely than the broader CWE-287."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (a020fa47b6c3cb5b43d841afe2ccf149889fad6b): fix: [security] Refuse a TOTP code that was already used to",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/a020fa47b.patch"
],
"timestamp": "2026-09-23T14:24:44Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20194"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103655",
"datePublished": "2026-10-01T08:08:55.013Z",
"dateReserved": "2026-10-01T08:08:52.909Z",
"dateUpdated": "2026-10-01T15:25:55.269Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103659 (GCVE-0-2026-103659)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:33 – Updated: 2026-10-01 15:24qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:10 - Model
qwen3.8:27b- Input
-
patch set (2 sources)
e74b42214be0… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
ab08edf9256b
|
fix: [security] Apply the object ACL to flattened attributes | ebc10168f16d… |
07f3486d50f2
|
fix: [event] Gate flattened attributes on the object ACL | 18601512c29d… |
Fix summary
The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.
Patch summary
In app/Model/Event.php, two code paths were modified. In fetchPaginatedAttributes(), a new subquery is generated against the Object table using the distribution and sharing-group ACL conditions, and an OR condition is added to the attribute query: either Attribute.object_id = 0 (top-level attribute) or the attribute's object passes the ACL. In fetchEvent(), when flatten is true and the user is not a site admin, a similar subquery is injected into the Attribute contain conditions. The second commit refactors the ACL condition into a standalone variable ($objectAclCondition) and uses only that condition (plus Object.id = Attribute.object_id) in the subquery, removing the soft-delete and other contain conditions that were incorrectly included. A regression test class (FlattenedObjectAcl) in tests/testregressions.py verifies: (1) an outsider cannot see organisation-only object attributes via flatten, (2) the owner retains soft-deleted attributes of a live object, and (3) the outsider cannot see another org's soft
CVSS rationale
AV:N - exploited over the network via the MISP REST API. AC:L - the attack is a simple API request with the flatten parameter; no race conditions or complex setup required. AT:N - no special target-side conditions beyond the existence of a community event with restricted objects. PR:L - requires an authenticated user with at least read access to the community event. UI:N - no user interaction needed; the API call is self-contained. VC:H - sensitive threat-intelligence attributes from organisation-only objects are fully exposed to unauthorized users. VI:N, VA:N - no integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N - no impact on subsequent components; the data resides within the same application.
Weakness rationale
- CWE-862 The flattening code path removed the Object contain (which enforced distribution and sharing-group ACLs) without re-applying an equivalent authorization check on the resulting top-level attributes. The object-level access control was simply absent from the flattened query, allowing unauthorized data access.
- CWE-285 The authorization decision for object attributes was based solely on the event-level distribution rather than the object-level distribution and sharing group. This is an improper authorization check that grants broader access than intended.
Attack pattern rationale
- CAPEC-126 The attacker (a legitimate user with access to a community event) exploits the fact that the application's privilege/access-control enforcement is incorrectly adjusted during the flatten operation. The object-level ACL is not applied, effectively elevating the user's data access beyond their intended scope. This is the closest CAPEC pattern to an authorization bypass where the application fails to enforce a narrower access control in a specific code path. Uncertainty: no CAPEC pattern specifically describes 'missing per-object ACL in a flattened view'; CAPEC-126 is the best available match for privilege/access-control bypass.
Assumptions to verify
- The affected version range is unspecified; the patch does not include version tags or release boundaries. All MISP versions prior to the fix commit are assumed affected.
- The CVSS PR:L assumes the attacker needs at minimum a read-access role on the community event; no evidence supports a lower or higher privilege requirement.
- The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a missing per-object ACL in a flattened API response. The mapping is approximate.
- The second commit (soft-delete fix) is treated as part of the same vulnerability remediation per the patch-set assumption, though it addresses a regression introduced by the first fix rather than the original authorization bypass.
- AI co-authors (Claude Opus 4.8, Claude Opus 5) are listed in commit metadata but are not included as advisory credits as they are tooling, not human contributors.
- No evidence of active exploitation, public PoC, or in-the-wild abuse was found in the supplied data.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 11 | medium | 6 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c): fix: [security] Apply the object ACL to flattened attributes",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/ab08edf92.patch"
],
"timestamp": "2026-09-23T07:25:31Z",
"type": "fix-developed"
},
{
"description": "Corrective change authored (07f3486d50f2a5ee0f31ea66c920692664397ddb): fix: [event] Gate flattened attributes on the object ACL",
"id": "evt-fix-developed-2",
"references": [
"https://github.com/MISP/MISP/commit/07f3486d5.patch"
],
"timestamp": "2026-09-28T11:41:23Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103659",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:24:35.363182Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:24:42.585Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Event model (app/Model/Event.php)"
],
"product": "MISP",
"programFiles": [
"app/Model/Event.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes.\u003c/p\u003e\u003cp\u003eAs a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user\u0027s organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data.\u003c/p\u003e\u003cp\u003eA secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with access to a community-distributed event\u003c/p\u003e\u003cp\u003e- The event contains at least one object with a distribution level or sharing group that restricts access beyond the event\u0027s own distribution\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Unauthorized disclosure of attributes belonging to restricted objects\u003c/p\u003e\u003cp\u003e- Potential exposure of organisation-specific threat intelligence to other organisations\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes.\n\nAs a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user\u0027s organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data.\n\nA secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate.\n\nPreconditions:\n\n- An authenticated user with access to a community-distributed event\n\n- The event contains at least one object with a distribution level or sharing group that restricts access beyond the event\u0027s own distribution\n\nImpact:\n\n- Unauthorized disclosure of attributes belonging to restricted objects\n\n- Potential exposure of organisation-specific threat intelligence to other organisations\n\nAffected versions: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Exploiting Incorrectly Adjusted Privileges"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:10:59Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:33:05.141Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/ab08edf92"
},
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/07f3486d5"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.\u003c/p\u003e"
}
],
"value": "The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner."
}
],
"title": "MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version range is unspecified; the patch does not include version tags or release boundaries. All MISP versions prior to the fix commit are assumed affected.",
"The CVSS PR:L assumes the attacker needs at minimum a read-access role on the community event; no evidence supports a lower or higher privilege requirement.",
"The CAPEC-126 mapping is the closest available pattern; no CAPEC specifically describes a missing per-object ACL in a flattened API response. The mapping is approximate.",
"The second commit (soft-delete fix) is treated as part of the same vulnerability remediation per the patch-set assumption, though it addresses a regression introduced by the first fix rather than the original authorization bypass.",
"AI co-authors (Claude Opus 4.8, Claude Opus 5) are listed in commit metadata but are not included as advisory credits as they are tooling, not human contributors.",
"No evidence of active exploitation, public PoC, or in-the-wild abuse was found in the supplied data."
],
"capecRationale": [
{
"capecId": "CAPEC-126",
"rationale": "The attacker (a legitimate user with access to a community event) exploits the fact that the application\u0027s privilege/access-control enforcement is incorrectly adjusted during the flatten operation. The object-level ACL is not applied, effectively elevating the user\u0027s data access beyond their intended scope. This is the closest CAPEC pattern to an authorization bypass where the application fails to enforce a narrower access control in a specific code path. Uncertainty: no CAPEC pattern specifically describes \u0027missing per-object ACL in a flattened view\u0027; CAPEC-126 is the best available match for privilege/access-control bypass."
}
],
"commit": "07f3486d50f2a5ee0f31ea66c920692664397ddb",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Wenhao Wu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 4.8"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "AV:N - exploited over the network via the MISP REST API. AC:L - the attack is a simple API request with the flatten parameter; no race conditions or complex setup required. AT:N - no special target-side conditions beyond the existence of a community event with restricted objects. PR:L - requires an authenticated user with at least read access to the community event. UI:N - no user interaction needed; the API call is self-contained. VC:H - sensitive threat-intelligence attributes from organisation-only objects are fully exposed to unauthorized users. VI:N, VA:N - no integrity or availability impact on the vulnerable component. SC:N, SI:N, SA:N - no impact on subsequent components; the data resides within the same application.",
"fixSummary": "The fix re-applies the object distribution and sharing-group ACL as a subquery condition on the Attribute.object_id field whenever the flatten option is active. This ensures that attributes belonging to objects the caller is not authorized to see are excluded from the flattened result set. The second commit refines the gate to use only the distribution ACL condition (correlated on Object.id) rather than the entire Object contain, preventing soft-delete state from incorrectly filtering attributes for the event owner.",
"generatedAt": "2026-10-01T08:10:59.855811Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 6,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "e74b42214be094a3c715d859dd20b9ecd7091d30a187ab4583a7ec0f070c0581",
"patchSummary": "In app/Model/Event.php, two code paths were modified. In fetchPaginatedAttributes(), a new subquery is generated against the Object table using the distribution and sharing-group ACL conditions, and an OR condition is added to the attribute query: either Attribute.object_id = 0 (top-level attribute) or the attribute\u0027s object passes the ACL. In fetchEvent(), when flatten is true and the user is not a site admin, a similar subquery is injected into the Attribute contain conditions. The second commit refactors the ACL condition into a standalone variable ($objectAclCondition) and uses only that condition (plus Object.id = Attribute.object_id) in the subquery, removing the soft-delete and other contain conditions that were incorrectly included. A regression test class (FlattenedObjectAcl) in tests/testregressions.py verifies: (1) an outsider cannot see organisation-only object attributes via flatten, (2) the owner retains soft-deleted attributes of a live object, and (3) the outsider cannot see another org\u0027s soft",
"patchTruncated": false,
"patches": [
{
"commit": "ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c",
"date": "Wed, 23 Sep 2026 09:25:31 +0200",
"patchSha256": "ebc10168f16d00a458d924a62fe76e00277217c8449c694eeb4442d6d3a724a0",
"source": "https://github.com/MISP/MISP/commit/ab08edf92.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/ab08edf92.patch",
"subject": "fix: [security] Apply the object ACL to flattened attributes"
},
{
"commit": "07f3486d50f2a5ee0f31ea66c920692664397ddb",
"date": "Mon, 28 Sep 2026 13:41:23 +0200",
"patchSha256": "18601512c29df510bfdc629de713cffd41af868e7d230374aa346c92829e40de",
"source": "https://github.com/MISP/MISP/commit/07f3486d5.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/07f3486d5.patch",
"subject": "fix: [event] Gate flattened attributes on the object ACL"
}
],
"source": "patch set (2 sources)",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:10:59Z",
"version": "2.0.3"
},
"subject": "fix: [event] Gate flattened attributes on the object ACL",
"weaknessRationale": [
{
"cweId": "CWE-862",
"rationale": "The flattening code path removed the Object contain (which enforced distribution and sharing-group ACLs) without re-applying an equivalent authorization check on the resulting top-level attributes. The object-level access control was simply absent from the flattened query, allowing unauthorized data access."
},
{
"cweId": "CWE-285",
"rationale": "The authorization decision for object attributes was based solely on the event-level distribution rather than the object-level distribution and sharing group. This is an improper authorization check that grants broader access than intended."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (ab08edf9256bb3c9c8a382e0778ecd10b9e29c7c): fix: [security] Apply the object ACL to flattened attributes",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/ab08edf92.patch"
],
"timestamp": "2026-09-23T07:25:31Z",
"type": "fix-developed"
},
{
"description": "Corrective change authored (07f3486d50f2a5ee0f31ea66c920692664397ddb): fix: [event] Gate flattened attributes on the object ACL",
"id": "evt-fix-developed-2",
"references": [
"https://github.com/MISP/MISP/commit/07f3486d5.patch"
],
"timestamp": "2026-09-28T11:41:23Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20257"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103659",
"datePublished": "2026-10-01T08:33:05.141Z",
"dateReserved": "2026-10-01T08:33:03.219Z",
"dateUpdated": "2026-10-01T15:24:42.585Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103662 (GCVE-0-2026-103662)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:48 – Updated: 2026-10-01 15:07- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/9619083c8 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:34 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/9619083c8.patch
0255a5f82ee8… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
9619083c8cea
|
fix: [security] Escape the tag name on the taxonomy tag | 0255a5f82ee8… |
Fix summary
The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.
Patch summary
Two view template files (app/View/Taxonomies/add_tag.ctp and app/View/Taxonomies/disable_tag.ctp) are modified. In each file, the raw request data value $this->request->data['Taxonomy']['name'] is wrapped with CakePHP's h() HTML-encoding helper function before being passed to the translation string that renders the confirmation description. This is a one-line change per file, adding the h() wrapper around the previously unescaped variable.
CVSS rationale
AV:N - the vulnerability is exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; simply visiting a crafted URL triggers the XSS. AT:N - no attack target manipulation required. PR:N - the attacker does not need authentication; they craft a URL for the admin to visit. UI:A - the administrator must actively navigate to the malicious URL. VC:L - the XSS can read session cookies and page data in the admin's browser. VI:L - the XSS can perform actions on behalf of the admin within the MISP interface. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the victim's browser session; no secondary system impact is evidenced.
Weakness rationale
- CWE-79 The patch directly addresses a reflected XSS: user-controlled input from the request is echoed into HTML output without encoding. The fix applies HTML entity encoding (h() helper), which is the canonical remediation for CWE-79.
Attack pattern rationale
- CAPEC-63 The commit message explicitly states the tag name is 'echoed from the URL unescaped, a reflected XSS.' The attacker supplies a malicious value via a URL parameter, the application reflects it into the HTML response without encoding, and the script executes in the victim's browser. This is a textbook reflected XSS pattern matching CAPEC-63 exactly.
Assumptions to verify
- The tag v2.5.48 is assumed to be the first release containing the fix based on the tag_version_boundary metadata showing 44 commits after the fix commit; the exact release version that first shipped the fix is not explicitly stated.
- The vulnerability requires the legacy taxonomy tag confirmation views to be in use; if MISP has migrated to a different UI for taxonomy management, the attack surface may not be reachable.
- PR:N is assumed because the attacker does not need their own MISP account; they only need to deliver a crafted URL to an authenticated admin. If the form is only reachable via authenticated session and the parameter cannot be injected via URL for unauthenticated users, PR could be elevated.
- The Co-Authored-By line references an AI tool (Claude Opus 5.5); this is not credited as a human contributor per standard CVE credit practices.
- CAPEC-63 is selected as the closest match; the exact CAPEC taxonomy does not have a more specific entry for reflected XSS in server-rendered template engines.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
8 | 11 | high | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (9619083c8cea496fd3ddbad5bf9be57c91fd2118): fix: [security] Escape the tag name on the taxonomy tag",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/9619083c8.patch"
],
"timestamp": "2026-09-23T09:17:07Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103662",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:07:07.862444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:07:17.448Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"Taxonomies (add_tag",
"disable_tag views)"
],
"product": "MISP",
"programFiles": [
"app/View/Taxonomies/add_tag.ctp",
"app/View/Taxonomies/disable_tag.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).\u003c/p\u003e\u003cp\u003eThe affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator\u0027s browser session.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.\u003c/p\u003e\u003cp\u003e- The victim must be an authenticated site administrator.\u003c/p\u003e\u003cp\u003e- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary client-side script in the context of the administrator\u0027s browser.\u003c/p\u003e\u003cp\u003e- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.\u003c/p\u003e\u003cp\u003e- Potential for performing privileged actions on behalf of the administrator within the MISP interface.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
}
],
"value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).\n\nThe affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator\u0027s browser session.\n\nPreconditions:\n\n- The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.\n\n- The victim must be an authenticated site administrator.\n\n- The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).\n\nSecurity impact:\n\n- Execution of arbitrary client-side script in the context of the administrator\u0027s browser.\n\n- Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.\n\n- Potential for performing privileged actions on behalf of the administrator within the MISP interface.\n\nAffected versions: \u003c2.5.48."
}
],
"impacts": [
{
"capecId": "CAPEC-63",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-63 Reflected Cross-Site Scripting"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:34:46Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:48:38.222Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/9619083c8"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector."
}
],
"title": "MISP Reflected XSS in Taxonomy Tag Confirmation Forms",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The tag v2.5.48 is assumed to be the first release containing the fix based on the tag_version_boundary metadata showing 44 commits after the fix commit; the exact release version that first shipped the fix is not explicitly stated.",
"The vulnerability requires the legacy taxonomy tag confirmation views to be in use; if MISP has migrated to a different UI for taxonomy management, the attack surface may not be reachable.",
"PR:N is assumed because the attacker does not need their own MISP account; they only need to deliver a crafted URL to an authenticated admin. If the form is only reachable via authenticated session and the parameter cannot be injected via URL for unauthenticated users, PR could be elevated.",
"The Co-Authored-By line references an AI tool (Claude Opus 5.5); this is not credited as a human contributor per standard CVE credit practices.",
"CAPEC-63 is selected as the closest match; the exact CAPEC taxonomy does not have a more specific entry for reflected XSS in server-rendered template engines."
],
"capecRationale": [
{
"capecId": "CAPEC-63",
"rationale": "The commit message explicitly states the tag name is \u0027echoed from the URL unescaped, a reflected XSS.\u0027 The attacker supplies a malicious value via a URL parameter, the application reflects it into the HTML response without encoding, and the script executes in the victim\u0027s browser. This is a textbook reflected XSS pattern matching CAPEC-63 exactly."
}
],
"commit": "9619083c8cea496fd3ddbad5bf9be57c91fd2118",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - the vulnerability is exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; simply visiting a crafted URL triggers the XSS. AT:N - no attack target manipulation required. PR:N - the attacker does not need authentication; they craft a URL for the admin to visit. UI:A - the administrator must actively navigate to the malicious URL. VC:L - the XSS can read session cookies and page data in the admin\u0027s browser. VI:L - the XSS can perform actions on behalf of the admin within the MISP interface. VA:N - no availability impact. SC/SI/SA:N - the impact is confined to the victim\u0027s browser session; no secondary system impact is evidenced.",
"fixSummary": "The vulnerability is remediated by HTML-encoding the user-supplied tag name value before it is interpolated into the confirmation form description text. This ensures that any HTML metacharacters in the input are rendered as inert text rather than executable markup, neutralizing the reflected XSS vector.",
"generatedAt": "2026-10-01T08:34:46.777011Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 8
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "0255a5f82ee8c34e3f27c236a85f0dfc4379393d7e75c42d4d33fbc6d6b151ac",
"patchSummary": "Two view template files (app/View/Taxonomies/add_tag.ctp and app/View/Taxonomies/disable_tag.ctp) are modified. In each file, the raw request data value $this-\u003erequest-\u003edata[\u0027Taxonomy\u0027][\u0027name\u0027] is wrapped with CakePHP\u0027s h() HTML-encoding helper function before being passed to the translation string that renders the confirmation description. This is a one-line change per file, adding the h() wrapper around the previously unescaped variable.",
"patchTruncated": false,
"patches": [
{
"commit": "9619083c8cea496fd3ddbad5bf9be57c91fd2118",
"date": "Wed, 23 Sep 2026 11:17:07 +0200",
"patchSha256": "0255a5f82ee8c34e3f27c236a85f0dfc4379393d7e75c42d4d33fbc6d6b151ac",
"source": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"subject": "fix: [security] Escape the tag name on the taxonomy tag"
}
],
"source": "https://github.com/MISP/MISP/commit/9619083c8.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:34:46Z",
"version": "2.0.3"
},
"subject": "fix: [security] Escape the tag name on the taxonomy tag",
"tagVersionBoundary": {
"commits_after_fix": 44,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The patch directly addresses a reflected XSS: user-controlled input from the request is echoed into HTML output without encoding. The fix applies HTML entity encoding (h() helper), which is the canonical remediation for CWE-79."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (9619083c8cea496fd3ddbad5bf9be57c91fd2118): fix: [security] Escape the tag name on the taxonomy tag",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/9619083c8.patch"
],
"timestamp": "2026-09-23T09:17:07Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20300"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103662",
"datePublished": "2026-10-01T08:48:38.222Z",
"dateReserved": "2026-10-01T08:48:36.324Z",
"dateUpdated": "2026-10-01T15:07:17.448Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103664 (GCVE-0-2026-103664)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:55 – Updated: 2026-10-01 15:06- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/58925dbf0 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 08:49 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/58925dbf0.patch
7e384946a0fb… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
58925dbf01c2
|
fix: [security] Cast the analyst data seed to an integer | 7e384946a0fb… |
Fix summary
The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.
Patch summary
In AttributesController.php and ObjectsController.php, the seed value set for the view is now cast to an integer with a fallback to a random integer if the cast yields zero. In the two analyst data view templates (generic_simple.ctp and thread.ctp), the seed variable is similarly cast to an integer before use in inline script, replacing the previous logic that only checked for emptiness without type enforcement.
CVSS rationale
AV:N - exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; a simple URL with a malicious seed suffices. AT:N - no prior manipulation of the target system needed. PR:L - MISP is an authenticated platform; the attacker needs at least a low-privilege account or must target an authenticated user. UI:A - the victim must actively navigate to the crafted URL. VC/VI/VA:N - the server-side confidentiality, integrity, and availability are not directly impacted. SC:L - the victim's browser session data (cookies, tokens) can be read. SI:L - the victim's page content can be modified. SA:N - no impact on security authority.
Weakness rationale
- CWE-79 The user-supplied seed parameter was reflected into inline JavaScript in the HTML response without sanitization or type coercion, allowing script injection. This is a textbook reflected XSS.
Attack pattern rationale
- CAPEC-1 The attacker supplies a malicious value in a URL parameter (seed), which the server reflects unmodified into inline JavaScript in the HTTP response. The victim's browser executes the injected script. This matches the reflected XSS pattern precisely. No uncertainty in this mapping.
Assumptions to verify
- MISP requires user authentication to access the analyst data views; PR:L assumes a low-privilege authenticated account is sufficient for the attacker to craft or deliver the malicious URL.
- The exact fixed version number is not stated in the patch; the fix commit is 32 commits after the v2.5.48 tag, so the fixed version is presumed to be a release after 2.5.48.
- The UI:A rating assumes the victim must click a link or navigate to the crafted URL; if the seed could be injected via a different vector requiring no user interaction, UI could be None.
- CAPEC-1 (Reflected XSS) is selected as the closest match; the injection occurs server-side into the HTML response, distinguishing it from DOM-based XSS (CAPEC-64).
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
9 | 11 | high | 4 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (58925dbf01c2fe5dfe9b2f61a421f6463f66ca56): fix: [security] Cast the analyst data seed to an integer",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/58925dbf0.patch"
],
"timestamp": "2026-09-24T16:06:24Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103664",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:06:14.886463Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:06:25.374Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"AttributesController::viewAnalystData",
"ObjectsController::viewAnalystData",
"Analyst_data view templates"
],
"product": "MISP",
"programFiles": [
"app/Controller/AttributesController.php",
"app/Controller/ObjectsController.php",
"app/View/Elements/genericElements/Analyst_data/generic_simple.ctp",
"app/View/Elements/genericElements/Analyst_data/thread.ctp"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\u003c/p\u003e\u003cp\u003eAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim\u0027s browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\u003c/p\u003e\u003cp\u003e- The attacker must supply a malicious seed value in the URL path.\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Execution of arbitrary JavaScript in the victim\u0027s browser session.\u003c/p\u003e\u003cp\u003e- Potential theft of session credentials or sensitive data visible in the page.\u003c/p\u003e\u003cp\u003e- Manipulation of the analyst data interface.\u003c/p\u003e\u003cp\u003eAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).\u003c/p\u003e"
}
],
"value": "MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement.\n\nAn attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim\u0027s browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim.\n\nPreconditions:\n\n- The victim must be authenticated to MISP and access the analyst data view for an attribute or object.\n\n- The attacker must supply a malicious seed value in the URL path.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim\u0027s browser session.\n\n- Potential theft of session credentials or sensitive data visible in the page.\n\n- Manipulation of the analyst data interface.\n\nAffected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48)."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 XSS - Reflected"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:49:54Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:55:51.589Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/58925dbf0"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.\u003c/p\u003e"
}
],
"value": "The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector."
}
],
"title": "MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"MISP requires user authentication to access the analyst data views; PR:L assumes a low-privilege authenticated account is sufficient for the attacker to craft or deliver the malicious URL.",
"The exact fixed version number is not stated in the patch; the fix commit is 32 commits after the v2.5.48 tag, so the fixed version is presumed to be a release after 2.5.48.",
"The UI:A rating assumes the victim must click a link or navigate to the crafted URL; if the seed could be injected via a different vector requiring no user interaction, UI could be None.",
"CAPEC-1 (Reflected XSS) is selected as the closest match; the injection occurs server-side into the HTML response, distinguishing it from DOM-based XSS (CAPEC-64)."
],
"capecRationale": [
{
"capecId": "CAPEC-1",
"rationale": "The attacker supplies a malicious value in a URL parameter (seed), which the server reflects unmodified into inline JavaScript in the HTTP response. The victim\u0027s browser executes the injected script. This matches the reflected XSS pattern precisely. No uncertainty in this mapping."
}
],
"commit": "58925dbf01c2fe5dfe9b2f61a421f6463f66ca56",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N - exploitable over the network via a crafted URL. AC:L - no race conditions or special conditions; a simple URL with a malicious seed suffices. AT:N - no prior manipulation of the target system needed. PR:L - MISP is an authenticated platform; the attacker needs at least a low-privilege account or must target an authenticated user. UI:A - the victim must actively navigate to the crafted URL. VC/VI/VA:N - the server-side confidentiality, integrity, and availability are not directly impacted. SC:L - the victim\u0027s browser session data (cookies, tokens) can be read. SI:L - the victim\u0027s page content can be modified. SA:N - no impact on security authority.",
"fixSummary": "The vulnerability is remediated by enforcing integer type on the seed parameter at both the controller layer and the view/template layer. Casting the value to an integer ensures that any non-numeric input (including script payloads) is neutralized before it reaches the inline JavaScript context, eliminating the injection vector.",
"generatedAt": "2026-10-01T08:49:54.035056Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 4,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 9
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37",
"patchSummary": "In AttributesController.php and ObjectsController.php, the seed value set for the view is now cast to an integer with a fallback to a random integer if the cast yields zero. In the two analyst data view templates (generic_simple.ctp and thread.ctp), the seed variable is similarly cast to an integer before use in inline script, replacing the previous logic that only checked for emptiness without type enforcement.",
"patchTruncated": false,
"patches": [
{
"commit": "58925dbf01c2fe5dfe9b2f61a421f6463f66ca56",
"date": "Thu, 24 Sep 2026 18:06:24 +0200",
"patchSha256": "7e384946a0fb4f1d43dee43a5374cabf2e70c31add4a6d2e4fa845cdc5ee5b37",
"source": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"subject": "fix: [security] Cast the analyst data seed to an integer"
}
],
"source": "https://github.com/MISP/MISP/commit/58925dbf0.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T08:49:54Z",
"version": "2.0.3"
},
"subject": "fix: [security] Cast the analyst data seed to an integer",
"tagVersionBoundary": {
"commits_after_fix": 32,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-79",
"rationale": "The user-supplied seed parameter was reflected into inline JavaScript in the HTML response without sanitization or type coercion, allowing script injection. This is a textbook reflected XSS."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (58925dbf01c2fe5dfe9b2f61a421f6463f66ca56): fix: [security] Cast the analyst data seed to an integer",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/58925dbf0.patch"
],
"timestamp": "2026-09-24T16:06:24Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20241"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103664",
"datePublished": "2026-10-01T08:55:51.589Z",
"dateReserved": "2026-10-01T08:55:49.992Z",
"dateUpdated": "2026-10-01T15:06:25.374Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103858 (GCVE-0-2026-103858)
Vulnerability from cvelistv5 – Published: 2026-10-01 11:31 – Updated: 2026-10-01 15:00- CWE-285 - Improper Authorization
| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/79fbd4c75 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02bcp-05-x-03
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-10-01 11:16 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/79fbd4c75.patch
04551eba9b01… - Confidence
- medium
| Commit | Subject | Patch SHA-256 |
|---|---|---|
79fbd4c7580a
|
fix: [security] Apply the thread ACL when posting to a | 04551eba9b01… |
Fix summary
The fix replaces the limited org-only distribution check with a call to the thread's full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post's thread_id was added to prevent referencing posts without a valid thread association.
Patch summary
In PostsController.php add() method: (1) For the 'thread' target case, replaced the inline distribution==0 and org_id comparison with a call to Thread->checkIfAuthorised() before reading the thread; removed the separate _isSiteAdmin() bypass. (2) For the 'post' target case, added a check that the post has a non-empty thread_id, replaced the same limited distribution/org check with Thread->checkIfAuthorised(), and reordered the thread read to occur after the authorization check. Net: 8 insertions, 12 deletions in one file.
CVSS rationale
AV:N: web application accessible over network. AC:L: attacker only needs a valid thread_id or post_id, no race conditions or special timing. AT:N: no special attack prerequisites beyond authentication. PR:L: requires an authenticated MISP user account. UI:N: no victim interaction needed; the attacker directly issues the request. VC:L: attacker can read thread titles and quoted post content they should not see. VI:L: attacker can inject posts into unauthorized threads. VA:N: no availability impact. SC/SI/SA:N: no impact on subsequent components. The impact is bounded to the MISP instance's data and does not compromise the server or other systems.
Weakness rationale
- CWE-285 The authorization check was present but incomplete: it only verified org-level distribution (distribution==0) and org_id match, failing to enforce sharing-group membership and event-level ACL. This is a classic case of insufficient authorization logic rather than a completely missing check, making CWE-285 more precise than CWE-862.
Attack pattern rationale
- CAPEC-10 The attacker manipulates the target_id parameter (thread_id or post_id) in the posts/add request to reference a thread or post they do not have full access to. The incomplete server-side authorization check then permits the operation. CAPEC-10 is the closest available pattern for exploiting a server's failure to properly validate the authorization context of a user-supplied resource identifier. Uncertainty: no CAPEC specifically named 'Insecure Direct Object Reference' or 'Broken Access Control via Incomplete ACL' exists in the CAPEC catalog, so Parameter Tampering is the best available match.
Assumptions to verify
- The exact affected version range is uncertain; the tag boundary v2.5.48 with 42 commits after the fix suggests the fix landed around or before v2.5.48, but the precise first-affected and first-fixed versions are not stated in the patch.
- The checkIfAuthorised() method is assumed to enforce the full thread ACL including sharing groups and event visibility, based on the commit message description; the method's implementation is not included in the patch.
- CAPEC-10 (Parameter Tampering) is the closest available CAPEC mapping; no CAPEC specifically covers 'incomplete authorization check on a direct object reference' was identified in the catalog.
- The CVSS assumes the attacker already possesses a valid MISP account (PR:L); unauthenticated access is not indicated by the patch.
- The AI co-author (Claude Opus 5.5) is credited as a tool rather than a person, per the Co-Authored-By line.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
7 | 11 | medium | 5 |
{
"x_timeline": {
"events": [
{
"description": "Corrective change authored (79fbd4c7580adc0518581351c3d8c3d5b3ac7c97): fix: [security] Apply the thread ACL when posting to a",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/79fbd4c75.patch"
],
"timestamp": "2026-09-23T13:27:08Z",
"type": "fix-developed"
}
]
}
}
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103858",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:00:37.761849Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:00:57.587Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"modules": [
"PostsController (discussion/thread posting)"
],
"product": "MISP",
"programFiles": [
"app/Controller/PostsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "unspecified",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy and C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.\u003c/p\u003e\u003cp\u003eAs a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:\u003c/p\u003e\u003cp\u003e- Read the thread title and the content of the quoted post\u003c/p\u003e\u003cp\u003e- Submit a new post into the discussion thread\u003c/p\u003e\u003cp\u003eThis constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).\u003c/p\u003e\u003cp\u003eAffected: \u0026lt;2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether the target thread was restricted to a single organization (org-only distribution). It did not enforce the full thread access control list, including sharing-group membership and event-level visibility.\n\nAs a result, an authenticated user who is outside the relevant sharing group or who does not have visibility on the associated event could:\n\n- Read the thread title and the content of the quoted post\n\n- Submit a new post into the discussion thread\n\nThis constitutes both an information disclosure (reading restricted thread and post content) and an integrity issue (injecting content into a thread the user is not authorized to participate in).\n\nAffected: \u003c2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-10",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-10 Parameter Tampering"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"format": "SSVC",
"other": {
"content": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:16:47Z",
"version": "2.0.3"
},
"type": "SSVC"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285 Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T11:31:32.840Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/79fbd4c75"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association.\u003c/p\u003e"
}
],
"value": "The fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association."
}
],
"title": "MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The exact affected version range is uncertain; the tag boundary v2.5.48 with 42 commits after the fix suggests the fix landed around or before v2.5.48, but the precise first-affected and first-fixed versions are not stated in the patch.",
"The checkIfAuthorised() method is assumed to enforce the full thread ACL including sharing groups and event visibility, based on the commit message description; the method\u0027s implementation is not included in the patch.",
"CAPEC-10 (Parameter Tampering) is the closest available CAPEC mapping; no CAPEC specifically covers \u0027incomplete authorization check on a direct object reference\u0027 was identified in the catalog.",
"The CVSS assumes the attacker already possesses a valid MISP account (PR:L); unauthenticated access is not indicated by the patch.",
"The AI co-author (Claude Opus 5.5) is credited as a tool rather than a person, per the Co-Authored-By line."
],
"capecRationale": [
{
"capecId": "CAPEC-10",
"rationale": "The attacker manipulates the target_id parameter (thread_id or post_id) in the posts/add request to reference a thread or post they do not have full access to. The incomplete server-side authorization check then permits the operation. CAPEC-10 is the closest available pattern for exploiting a server\u0027s failure to properly validate the authorization context of a user-supplied resource identifier. Uncertainty: no CAPEC specifically named \u0027Insecure Direct Object Reference\u0027 or \u0027Broken Access Control via Incomplete ACL\u0027 exists in the CAPEC catalog, so Parameter Tampering is the best available match."
}
],
"commit": "79fbd4c7580adc0518581351c3d8c3d5b3ac7c97",
"confidence": "medium",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Bastien Bossiroy and C\u00e9lien Desteucq of NCIA"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5.5 (1M context)"
}
],
"cvssRationale": "AV:N: web application accessible over network. AC:L: attacker only needs a valid thread_id or post_id, no race conditions or special timing. AT:N: no special attack prerequisites beyond authentication. PR:L: requires an authenticated MISP user account. UI:N: no victim interaction needed; the attacker directly issues the request. VC:L: attacker can read thread titles and quoted post content they should not see. VI:L: attacker can inject posts into unauthorized threads. VA:N: no availability impact. SC/SI/SA:N: no impact on subsequent components. The impact is bounded to the MISP instance\u0027s data and does not compromise the server or other systems.",
"fixSummary": "The fix replaces the limited org-only distribution check with a call to the thread\u0027s full authorization method (checkIfAuthorised), which enforces the complete access control list including sharing groups and event-level visibility. The thread is only read after successful authorization, preventing disclosure of the title and content to unauthorized users. An additional null-check on the post\u0027s thread_id was added to prevent referencing posts without a valid thread association.",
"generatedAt": "2026-10-01T11:16:47.016611Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 11,
"assumptionCount": 5,
"confidence": "medium",
"model": "qwen3.8:27b",
"score": 7
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938",
"patchSummary": "In PostsController.php add() method: (1) For the \u0027thread\u0027 target case, replaced the inline distribution==0 and org_id comparison with a call to Thread-\u003echeckIfAuthorised() before reading the thread; removed the separate _isSiteAdmin() bypass. (2) For the \u0027post\u0027 target case, added a check that the post has a non-empty thread_id, replaced the same limited distribution/org check with Thread-\u003echeckIfAuthorised(), and reordered the thread read to occur after the authorization check. Net: 8 insertions, 12 deletions in one file.",
"patchTruncated": false,
"patches": [
{
"commit": "79fbd4c7580adc0518581351c3d8c3d5b3ac7c97",
"date": "Wed, 23 Sep 2026 15:27:08 +0200",
"patchSha256": "04551eba9b017a1a2ccf05a79c21466f3fd7095a42750bd2704d57b2e3730938",
"source": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"subject": "fix: [security] Apply the thread ACL when posting to a"
}
],
"source": "https://github.com/MISP/MISP/commit/79fbd4c75.patch",
"ssvc": {
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "Supplier",
"timestamp": "2026-10-01T11:16:47Z",
"version": "2.0.3"
},
"subject": "fix: [security] Apply the thread ACL when posting to a",
"tagVersionBoundary": {
"commits_after_fix": 42,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-285",
"rationale": "The authorization check was present but incomplete: it only verified org-level distribution (distribution==0) and org_id match, failing to enforce sharing-group membership and event-level ACL. This is a classic case of insufficient authorization logic rather than a completely missing check, making CWE-285 more precise than CWE-862."
}
]
}
},
"bcp-05-x-03": {
"x_timeline": {
"events": [
{
"description": "Corrective change authored (79fbd4c7580adc0518581351c3d8c3d5b3ac7c97): fix: [security] Apply the thread ACL when posting to a",
"id": "evt-fix-developed-1",
"references": [
"https://github.com/MISP/MISP/commit/79fbd4c75.patch"
],
"timestamp": "2026-09-23T13:27:08Z",
"type": "fix-developed"
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20244"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103858",
"datePublished": "2026-10-01T11:31:32.840Z",
"dateReserved": "2026-10-01T11:31:31.101Z",
"dateUpdated": "2026-10-01T15:00:57.587Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.