OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on the profile edit functionality, an authenticated attacker with low privileges can gain administrative privileges on the web application.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LCiteum Opencti
APPCiteum≤ 5.12.31
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2026-27960CRITICAL9.8PL ✓same product
OpenCTI: privilege escalation umożliwiający dostęp jako dowolny użytkownik
CVE-2026-39980CRITICAL9.1PL ✓same product
OpenCTI: Wykonanie dowolnego kodu JS przez niesanityzowane szablony EJS
CVE-2025-24977CRITICAL9.1PL ✓same product
OpenCTI: RCE przez nadużycie web-hooków przez uprzywilejowanego użytkownika
CVE-2026-35210HIGH7.1PL ✓same product
OpenCTI: Pominięcie weryfikacji uprawnień przez nagłówek HTTP
CVE-2026-44730HIGH7.2same product
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...