CVE-2026-103237 - MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows
CVE ID :CVE-2026-103237 Published : Sept. 30, 2026, 10:17 a.m. | 20 minutes ago Description :MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture,...