chiprook
← Security
SecuritySeptember 27, 2026, 23:20

CVE-2026-76822 in OpenCTI: readers can create cases

OpenCTI has an authorization flaw CVE-2026-76822 rated 4.3: the GraphQL mutations caseIncidentAdd, caseRfiAdd and caseRftAdd are protected only by authentication, with no capability check. Any account, including a reader, can create cases; it is fixed in version 7.260701.0.

CVE-2026-76822 in OpenCTI: readers can create cases
#OpenCTI
Read next
Security

ZoomEye: 6,050 VeloCloud Orchestrator systems exposed online amid CVE-2026-93952

Security

CVE-2026-32996: Privilege Escalation in Veeam Agent for Windows

Security

CVE-2026-86510: out-of-bounds write in D-Link DIR-822A L2TP daemon

Security

CVE-2026-76441: Access Control Bypass in Cisco Secure Email Gateway