CVE 9.8 CRITICAL

OpenCTI privilege escalation and unauthenticated access via default admin account_CVE-2026-27960

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration.

AI Analysis

Privilege escalation vulnerability allowing unauthenticated attackers to query the API as any existing user, including the default admin account.

Basic Information

ID CVE-2026-27960
Source GitHub_M
Published May 5, 2026 at 18:35

Affected Product

Vendor OpenCTI-Platform
Product opencti
Version >= 6.6.0, < 6.9.13
Affected Versions OpenCTI-Platform opencti >= 6.6.0, < 6.9.13

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor OpenCTI-Platform
Product OpenCTI
Version 6.6.0-6.9.12

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.