PT-2026-45867 · Opencti · Opencti

·

CVE-2026-35212

·

Published

2026-06-02

·

Updated

2026-06-05

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 7.260227.0
Description An issue exists in the rendering of email-message observable body data where the content of the body field is not appropriately sanitized. This allows for Cross-Site Scripting (XSS), a technique where malicious scripts are injected into trusted websites. The flaw requires user interaction and can be exploited by individuals sharing STIX data or through any ingester, potentially leading to Cross-Site Request Forgery (CSRF) and large-scale session theft.
Recommendations Update to version 7.260227.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35212
GHSA-RG6R-X26X-63VQ
PYSEC-2026-203

Affected Products

Opencti