CVE-2026-27960
OpenCTI versions 6.6.0 through 6.9.12 contain a privilege escalation vulnerability that allows unauthenticated attackers to query the API as any existing user, including the default admin account. This flaw has been fixed in version 6.9.13. As a workaround, administrators can disable the default admin account using the APP__ADMIN__EXTERNALLY_MANAGED configuration.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of OpenCTI versions 6.6.0 to 6.9.12.
Real-world impact
An attacker could gain unauthorized access to any user's API privileges, potentially leading to full system compromise.
Why this severity
CVSS v3.1 base score of 9.8 (Critical) due to network‑adjacent, low‑complexity attack requiring no privileges or user interaction, with high impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade OpenCTI to version 6.9.13 or later.
NVD-referenced vendor advisory
Timeline
- May 5, 2026 · May 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/OpenCTI-Platform/opencti/se…mitigationvendor advisory