PT-2025-30046 · Opencti · Opencti

Einfachanders

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-46732

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 6.6.6
Description OpenCTI is a platform for managing cyber threat intelligence knowledge and observables. An IDOR vulnerability exists in the GraphQL NotificationLineNotificationMarkReadMutation and NotificationLineNotificationDeleteMutation mutations. This allows an authenticated user to modify the read status or delete notifications belonging to other users if they know the UUID of the notification. When changing the read status, the user also receives the content of the notification.
Recommendations Update to version 6.6.6 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-46732
GHSA-535G-QP2C-H7VP
PYSEC-2025-181

Affected Products

Opencti