PT-2026-25902 · Opencti · Opencti

Daffyspider

+1

·

Published

2026-03-17

·

Updated

2026-03-17

·

CVE-2026-21886

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 6.9.1
Description OpenCTI is a platform for managing cyber threat intelligence knowledge and observables. A flaw exists in the 'IndividualDeletionDeleteMutation' GraphQL mutation, allowing the deletion of unrelated and sensitive objects, such as analysis reports. This is due to a lack of validation within the API, failing to confirm contextual relationships between the targeted object and the executed mutation.
Recommendations Update to version 6.9.1 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21886
GHSA-MHMX-J75V-2M6X
PYSEC-2026-117

Affected Products

Opencti