Junglewise Threat Intelligence

CVE-2026-35211: Filigran OpenCTI Code Injection in GraphQL API

CVE-2026-35211 · Severity: medium · CVSS 6.5 · Published 2026-07-08

Technologies: pycti (PyPI), Filigran Opencti. Vendors: PyPI.

Executive brief

OpenCTI is an open-source platform used by organizations to manage and analyze cyber threat intelligence. A security flaw in its search interface allows authorized users to run complex, unoptimized scripts on the underlying database server. An attacker could use this to overwhelm the system's processor, causing the platform to become slow or completely unavailable for all other users.

Technical details

A code injection vulnerability exists in the OpenCTI GraphQL API due to improper neutralization of user-supplied input in the FilterOperator enum. Authenticated users with the 'KNOWLEDGE' capability can provide arbitrary Elasticsearch Painless scripts via the 'script' filter operator. Because these scripts are passed to the Elasticsearch backend without validation or sanitization, an attacker can execute computationally intensive operations, such as infinite loops. This results in a Denial of Service (DoS) by exhausting cluster CPU resources. The issue is resolved in version 7.260401.0 by removing the script filter from the public API by default.

Affected products

  • Filigran OpenCTI < 7.260401.0

Timeline

  • 2026-03-31: patched: Fix committed to backend to move script usage to internal_script
  • 2026-04-01: advisory: Release 7.260401.0 published
  • 2026-07-01: disclosed: GitHub Security Advisory published
  • 2026-07-08: advisory: NVD published CVE-2026-35211

References

Related threats