CVE-2026-10868
MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification
Description
A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craft a modified request containing another user identifier, potentially causing updates to be applied to an unintended user account. Depending on the editable fields and the attacker’s privileges, this could allow unauthorized modification of user account attributes and impact account integrity. The issue was addressed by explicitly removing the User.id field from request data before processing the user edit operation.
INFO
Published Date :
June 4, 2026, 4:16 p.m.
Last Modified :
July 22, 2026, 8:10 p.m.
Remotely Exploit :
Yes !
Source :
5a6e4751-2f3f-4070-9419-94fb35b644e8
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 4.0 | CRITICAL | 5a6e4751-2f3f-4070-9419-94fb35b644e8 | ||||
| CVSS 4.0 | CRITICAL | 5a6e4751-2f3f-4070-9419-94fb35b644e8 |
Solution
- Filter user-supplied fields during user edit operations.
- Explicitly remove User.id from request data before processing.
- Implement robust input validation for all user-controlled fields.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-10868.
| URL | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/1be8c413b7104a889dfd30c5b1986e3ab17238e8 |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-10868 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-10868
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-10868 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-10868 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 22, 2026
Action Type Old Value New Value Added Translation Title: MISP, Description: Una vulnerabilidad de asignación masiva existe en la funcionalidad de edición de usuarios de MISP debido a un filtrado insuficiente de campos proporcionados por el usuario en UsersController::edit(). Al procesar solicitudes de edición, la aplicación aceptó un valor User.id controlado por el usuario de los datos de la solicitud. Un atacante autenticado podría elaborar una solicitud modificada que contenga otro identificador de usuario, lo que podría causar que las actualizaciones se apliquen a una cuenta de usuario no deseada. Dependiendo de los campos editables y los privilegios del atacante, esto podría permitir la modificación no autorizada de atributos de la cuenta de usuario y el impacto en la integridad de la cuenta. El problema se abordó eliminando explícitamente el campo User.id de los datos de la solicitud antes de procesar la operación de edición de usuario. -
CVE Modified by 5a6e4751-2f3f-4070-9419-94fb35b644e8
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'misp', 'product': 'misp', 'versions': [{'status': 'affected', 'version': '0', 'versionType': 'semver', 'lessThanOrEqual': '2.5.38'}], 'defaultStatus': 'unaffected'}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-10868', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-06-04T17:29:38.831542Z'} -
New CVE Received by 5a6e4751-2f3f-4070-9419-94fb35b644e8
Jun. 04, 2026
Action Type Old Value New Value Added Description A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An authenticated attacker could craft a modified request containing another user identifier, potentially causing updates to be applied to an unintended user account. Depending on the editable fields and the attacker’s privileges, this could allow unauthorized modification of user account attributes and impact account integrity. The issue was addressed by explicitly removing the User.id field from request data before processing the user edit operation. Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-269 Added Reference https://github.com/MISP/MISP/commit/1be8c413b7104a889dfd30c5b1986e3ab17238e8