CVE-2026-76822: OpenCTI case creation flaw bypasses permission model
OpenCTI, the open-source threat intelligence platform by Filigran, has a moderate authorization flaw tracked as CVE-2026-76822 with a CVSS score of 4.3. The caseIncidentAdd, caseRfiAdd and caseRftAdd mutations carried only the @auth decorator without capability checks, letting any authenticated user, including readers, create case objects. Versions below 7.260701.0 are affected.
- CVE-2026-76822 scores 4.3 on CVSS 3.1 with vector AV:N/AC:L/PR:L/UI:N
- Three case creation mutations had @auth but no capability decorator
- Fixed in OpenCTI 7.260701.0; 7.260811.0 also closes a critical companion flaw
- ZoomEye found 1046 internet-facing OpenCTI instances
Read next
Security