


Perceptive Security
SOC/SIEM Consultancy

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability …
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 22:04:11
Source:
nvd.nist.gov
Identity & Access, Security Tools, Web Technologies
CVE-2026-35210 is an authorization bypass vulnerability in OpenCTI, an open source cyber threat intelligence platform. Any authenticated user with KNOWLEDGE_KNUPDATE permission can exploit this flaw by injecting the 'synchronized-upsert: true' HTTP header to bypass Confidence Level validation and Object Marking restrictions. This allows attackers to downgrade confidence levels, remove sensitive security markings such as TLP:RED, and manipulate relationships across STIX object types including Indicators, ThreatActors, Malware, and Reports. The vulnerability poses a significant risk to the integrity of threat intelligence data managed within the platform. It was fixed in OpenCTI version 7.260326.0. Patches and details are available via the official GitHub repository including a security advisory, pull request, and commit reference.
Technical details
Mitigation steps:
Affected products:
OpenCTI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35210
https://github.com/OpenCTI-Platform/opencti/commit/134531ddf5ecf741006b7f0870b7c36711b96540
https://github.com/OpenCTI-Platform/opencti/pull/14243
https://github.com/OpenCTI-Platform/opencti/releases/tag/7.260326.0
https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-36fr-4m54-94mj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
