CVE-2026-35211 is a vulnerability in the OpenCTI GraphQL API that allows authenticated users with the KNOWLEDGE capability to pass user-supplied Elasticsearch Painless script values directly into search queries without validation or sanitization. This can lead to computationally expensive scripts consuming cluster CPU resources and degrading or denying service for all users. The issue is fixed in version [truncated]
CVE-2026-35210 is an authorization bypass vulnerability in OpenCTI, allowing any authenticated user with KNOWLEDGE_KNUPDATE permission to bypass Confidence Level validation and Object Marking restrictions by injecting the synchronized-upsert: true HTTP header. This enables attackers to downgrade confidence levels, remove security markings such as TLP:RED, manipulate relationships, and affect STIX object t [truncated]
## Summary CVE-2026-44730 is a HIGH severity (CVSS 7.2) privilege-escalation vulnerability in OpenCTI, an open-source cyber-threat-intelligence platform. Prior to version 6.9.7, an organization administrator can escalate their own privileges by adding a user from a different organization who already holds higher privileges. The root cause is an incorrect access-control list (ACL) on the `userEdit` → `rela [truncated]
CVE-2025-61782 is an open redirect vulnerability in OpenCTI's SAML authentication endpoint. The issue allows an attacker to manipulate the RelayState parameter to redirect users to any external URL, potentially leading to phishing and credential theft. This vulnerability has been patched in version 6.8.3. Defenders should assess exposure and apply the patch to prevent potential phishing attacks and creden [truncated]
CVE-2025-61781 is a high-severity vulnerability in OpenCTI, an open-source platform for managing cyber threat intelligence. The vulnerability exists in the GraphQL mutation 'WorkspacePopoverDeletionMutation', which allows users to delete workspace-related objects without proper authorization checks. This can be exploited by supplying an active UUID of another user, leading to unauthorized deletion of the [truncated]