CRITICAL🇵🇱 Wersja polska

CVE-2026-39980

CVSS 9.1v3.1pub. 2026-04-09upd. 2026-04-22

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaScript in the context of the OpenCTI platform process during notifier template execution. This vulnerability is fixed in 6.9.5.

🤖 AI Analysis
How it works

The safeEjs.ts file responsible for handling EJS templates does not perform proper validation and sanitization of input data (CWE-1336 — improper neutralization of special elements in templates). A user with permission to manage customization can inject malicious JavaScript code into a notifier template. When such a template is executed, the code is interpreted and run directly in the context of the OpenCTI application process on the server.

Impact

An attacker can execute arbitrary JavaScript code on the server side, which potentially leads to complete takeover of the platform instance, disclosure of sensitive intelligence data, and violation of system integrity and availability.

Mitigation & patch

OpenCTI should be updated to version 6.9.5 or newer, in which the vulnerability has been fixed. Details are available in the official release: https://github.com/OpenCTI-Platform/opencti/releases/tag/6.9.5

Who is affected

OpenCTI (Citeum) in all versions prior to 6.9.5

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Citeum Opencti

    APP
    Citeum
    < 6.9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-27960CRITICAL9.8PL ✓same product

OpenCTI: privilege escalation umożliwiający dostęp jako dowolny użytkownik

CVE-2025-24977CRITICAL9.1PL ✓same product

OpenCTI: RCE przez nadużycie web-hooków przez uprzywilejowanego użytkownika

CVE-2026-35210HIGH7.1PL ✓same product

OpenCTI: Pominięcie weryfikacji uprawnień przez nagłówek HTTP

CVE-2026-44730HIGH7.2same product

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...

CVE-2026-21887HIGH7.7same product

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...