HIGH🇵🇱 Wersja polska

CVE-2026-35210

CVSS 7.1v3.1pub. 2026-07-08upd. 2026-07-13

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows any authenticated user with KNOWLEDGE_KNUPDATE permission to bypass Confidence Level validation and Object Marking restrictions by injecting the synchronized-upsert: true HTTP header, enabling attackers to downgrade confidence levels, remove security markings such as TLP:RED, manipulate relationships, and affect STIX object types including Indicators, ThreatActors, Malware, and Reports. This issue is fixed in version 7.260326.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
  • Citeum Opencti

    APP
    Citeum
    < 7.260326.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-27960CRITICAL9.8PL ✓same product

OpenCTI: privilege escalation umożliwiający dostęp jako dowolny użytkownik

CVE-2026-39980CRITICAL9.1PL ✓same product

OpenCTI: Wykonanie dowolnego kodu JS przez niesanityzowane szablony EJS

CVE-2025-24977CRITICAL9.1PL ✓same product

OpenCTI: RCE przez nadużycie web-hooków przez uprzywilejowanego użytkownika

CVE-2026-44730HIGH7.2same product

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...

CVE-2026-21887HIGH7.7same product

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...