AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-104908.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.1CVSS 4.0 · 5a6e4751-2f3f-4070-9419-94fb35b644e8
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Oct 02, 2026

Disclosure summary

MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation. Impact: - A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership. - A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users. - A user could reassign a model's organisation to an arbitrary value. Preconditions: - Authenticated user with decaying-model permission (perm_decaying). - Network access to the MISP instance. Affected:

Source-reported weakness categories

CWE-285, CWE-915

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-104908

Open original source · Updated Oct 02, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-02T12:16:48-04:00
MODIFIED 2026-10-02T13:17:05-04:00
INGESTED 2026-10-06T11:45:30-04:00