CVE-2026-76822 in OpenCTI: readers can create cases
OpenCTI has an authorization flaw CVE-2026-76822 rated 4.3: the GraphQL mutations caseIncidentAdd, caseRfiAdd and caseRftAdd are protected only by authentication, with no capability check. Any account, including a reader, can create cases; it is fixed in version 7.260701.0.
- CVSS 4.3, vector AV:N/AC:L/PR:L/UI:N, integrity impact only
- OpenCTI installations below version 7.260701.0 are vulnerable
- ZoomEye found 1046 internet-facing OpenCTI instances
- The same patch batch includes critical sandbox escape GHSA-2872-rg44-j9gx
Read next
Security