PT-2026-25902 · Opencti · Opencti

Daffyspider

+1

·

Publicado

2026-03-17

·

Atualizado

2026-03-17

·

CVE-2026-21886

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 6.9.1
Description OpenCTI is a platform for managing cyber threat intelligence knowledge and observables. A flaw exists in the 'IndividualDeletionDeleteMutation' GraphQL mutation, allowing the deletion of unrelated and sensitive objects, such as analysis reports. This is due to a lack of validation within the API, failing to confirm contextual relationships between the targeted object and the executed mutation.
Recommendations Update to version 6.9.1 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21886
GHSA-MHMX-J75V-2M6X
PYSEC-2026-117

Produtos afetados

Opencti