Executive brief
OpenCTI is an open-source platform used by organizations to manage and share cyber threat intelligence. A security flaw allowed administrators of a specific organization within the platform to grant themselves higher permissions by improperly adding users from other organizations to their own. This could lead to unauthorized access to sensitive threat data and full control over the platform's operations.
Technical details
A privilege escalation vulnerability exists in OpenCTI's GraphQL API due to improper access control (CWE-284) on the 'userEdit' and 'relationAdd' functions. An attacker with organization administrator privileges can exploit this by adding a user from a different organization who possesses higher platform-wide privileges into their own organization. This action effectively grants the attacker the elevated permissions of the added user. The vulnerability is reachable over the network and requires high privileges to execute. It has been addressed in version 6.9.7.
Affected products
- Filigran OpenCTI < 6.9.7
- Filigran pycti < 6.9.7
Timeline
- 2026-05-05: disclosed: Reported by Wachizungu
- 2026-05-26: advisory: NVD published CVE-2026-44730
- 2026-05-28: advisory: GitHub Advisory published