DEV Community

jeffrey
jeffrey

Posted on

OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem

Vulnerability overview

CVE-2026-76822 is a moderate authorization flaw in OpenCTI, the open-source threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm scores it 4.3 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and credits SalusCyber1. CERT-Bund carries the advisory as WID-SEC-2026-3563. Viewed as a data problem, the bug is about provenance: the platform accepted case objects without verifying that the creator had the authority to make them.

How the authorization gap works

The GraphQL mutations caseIncidentAdd, caseRfiAdd and caseRftAdd were guarded by @auth and nothing else. @auth checks that a session exists. Capability decorators, using permissions such as the settings and knowledge scopes, check what the session may do. Because the capability layer was absent, every authenticated principal could create cases regardless of role.

Exploitation conditions

The requirements are minimal: network reachability, low complexity, low privileges and no user interaction. A single reader-level account is enough. The attacker does not need to defeat input validation, since the mutation accepts well-formed input; the authorization layer is the only defence that was supposed to apply.

Impact

Integrity is the only affected property. Unauthorized cases enter the same queues analysts work from, so the practical harm is wasted triage and distorted statistics. Because the objects persist, the platform owner must reconstruct provenance after the fact: which cases did an authorized role create, and which appeared without one.

Affected products and scope

OpenCTI versions below 7.260701.0 are vulnerable; 7.260701.0 is the fix. CERT-Bund lists Linux and UNIX as the affected operating systems. The companion critical advisory GHSA-2872-rg44-j9gx, a safeEjs notifier sandbox escape, is fixed in 7.260811.0.

Exposure context

ZoomEye returned 1046 instances for app="OpenCTI" and 0 for vul.cve="CVE-2026-76822" at the time of writing. The product count covers internet-facing deployments of any version and leaves out internal ones, and the CVE count is zero because an authorization flaw leaves nothing visible to an external scanner.

Remediation and mitigations

Upgrade to 7.260701.0 or later, and prefer 7.260811.0 for full coverage of the advisory batch. Then restore provenance: audit case creation against role assignments, remove or flag cases that no authorised role produced, and restrict authentication to principals the workflow genuinely needs. Add a regression test that requires a capability decorator on every case mutation so the gap cannot re-enter through a later change.

References

Top comments (0)