Junglewise Threat Intelligence

CVE-2026-27960: OpenCTI privilege escalation and authentication bypass in API

CVE-2026-27960 · Severity: critical · CVSS 9.8 · Published 2026-05-05

Technologies: Citeum Opencti, pycti (PyPI). Vendors: Citeum, PyPI.

Executive brief

OpenCTI is a platform used by organizations to manage and analyze cyber threat intelligence data. A critical security flaw allows unauthorized individuals to bypass authentication and access the system's API with the permissions of any user, including administrators. This could lead to the complete exposure of sensitive threat data, unauthorized modification of intelligence records, or full system takeover.

Technical details

A privilege escalation vulnerability (CWE-287) exists in OpenCTI versions 6.6.0 through 6.9.12 due to improper authentication checks. An unauthenticated remote attacker can exploit this flaw to perform API queries while impersonating any valid user account, including the default administrator. The attack requires no user interaction and has low complexity. Successful exploitation results in a total loss of confidentiality, integrity, and availability. The issue is resolved in version 6.9.13; a partial workaround involves disabling the default admin account via the APP__ADMIN__EXTERNALLY_MANAGED configuration.

Affected products

  • OpenCTI-Platform OpenCTI 6.6.0 to 6.9.12

Timeline

  • 2026-05-04: advisory: GitHub Security Advisory published
  • 2026-05-05: disclosed: CVE published to NVD

References

Related threats