9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration.
AI Analysis
Privilege escalation vulnerability allowing unauthenticated attackers to query the API as any existing user, including the default admin account.
Basic Information
ID
CVE-2026-27960
Source
GitHub_M
Published
May 5, 2026 at 18:35
Affected Product
Vendor
OpenCTI-Platform
Product
opencti
Version
>= 6.6.0, < 6.9.13
Affected Versions
OpenCTI-Platform opencti >= 6.6.0, < 6.9.13
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
OpenCTI-Platform
Product
OpenCTI
Version
6.6.0-6.9.12