Junglewise Threat Intelligence

CVE-2026-35212: OpenCTI XSS in email-message observable body rendering

CVE-2026-35212 · Severity: low · CVSS 3.1 · Published 2026-06-02

Technologies: OpenCTI-Platform Opencti, pycti (PyPI). Vendors: PyPI.

Executive brief

OpenCTI, a platform used for managing cyber threat intelligence, contains a security flaw in how it displays email-related data. An attacker could send a specially crafted email message or threat intelligence file that, when viewed by a user, executes malicious code in their browser. This could allow an attacker to perform actions on behalf of the user or steal their login session, potentially compromising the entire threat intelligence database.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in OpenCTI versions prior to 7.260227.0. The vulnerability is located in the rendering component for 'email-message' observable body data, where input is not properly sanitized before being displayed in the web interface. An attacker can exploit this by injecting malicious scripts via STIX files or other data ingesters. Successful exploitation requires a user to view the malicious observable, which could then lead to Cross-Site Request Forgery (CSRF) and large-scale session hijacking. The issue is addressed in version 7.260227.0.

Affected products

  • OpenCTI-Platform OpenCTI < 7.260227.0

Timeline

  • 2026-06-01: advisory: GitHub Security Advisory published
  • 2026-06-02: disclosed: CVE-2026-35212 published to NVD

References

Related threats