Junglewise Threat Intelligence

CVE-2026-35210: Filigran OpenCTI authorization bypass via synchronized-upsert header

CVE-2026-35210 · Severity: high · CVSS 7.1 · Published 2026-07-08

Technologies: Filigran Opencti, pycti (PyPI). Vendors: PyPI.

Executive brief

OpenCTI is an open-source platform used by organizations to manage and share cyber threat intelligence. A security flaw allows authorized users to bypass data protection rules, such as 'TLP:RED' markings or confidence levels, by manipulating technical web headers. This could allow an insider or a compromised account to downgrade the reliability of threat data or remove sensitivity labels, potentially leading to the unauthorized disclosure or corruption of critical intelligence.

Technical details

An authorization bypass vulnerability exists in OpenCTI due to improper validation of the 'synchronized-upsert: true' HTTP header. Authenticated users possessing the 'KNOWLEDGE_KNUPDATE' permission can inject this header to bypass Confidence Level validation and Object Marking restrictions (such as TLP markings). This allows an attacker to downgrade confidence levels, remove security markings, and manipulate relationships across various STIX object types, including Indicators, Threat Actors, and Reports. The root cause is that the 'synchronized-upsert' functionality, intended for full synchronization by administrative/system processes, was accessible to standard users. The issue is fixed in version 7.260326.0.

Affected products

  • Filigran OpenCTI < 7.260326.0

Timeline

  • 2026-01-28: other: Pull request initiated to fix header usage
  • 2026-03-19: patched: Fix committed to master branch
  • 2026-03-26: advisory: Release 7.260326.0 published
  • 2026-07-08: disclosed: CVE-2026-35210 published

References

Related threats