OpenCTI Case Queue Integrity: Reading CVE-2026-76822 as a Data Provenance Problem
Vulnerability overview
CVE-2026-76822 is a moderate authorization flaw in OpenCTI, the open-source threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm scores it 4.3 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and credits SalusCyber1. CERT-Bund carries the advisory as WID-SEC-2026-3563. Viewed as a data problem, the bug is about provenance: the platform accepted case objects without verifying that the creator had the authority to make them.
How the authorization gap works
The GraphQL mutations caseIncidentAdd, caseRfiAdd and caseRftAdd were guarded by @auth and nothing else. @auth checks that a session exists. Capability decorators, using permissions such as the settings and knowledge scopes, check what the session may do. Because the capability layer was absent, every authenticated principal could create cases regardless of role.
Exploitation conditions
The requirements are minimal: network reachability, low complexity, low privileges and no user interaction. A single reader-level account is enough. The attacker does not need to defeat input validation, since the mutation accepts well-formed input; the authorization layer is the only defence that was supposed to apply.
Impact
Integrity is the only affected property. Unauthorized cases enter the same queues analysts work from, so the practical harm is wasted triage and distorted statistics. Because the objects persist, the platform owner must reconstruct provenance after the fact: which cases did an authorized role create, and which appeared without one.
Affected products and scope
OpenCTI versions below 7.260701.0 are vulnerable; 7.260701.0 is the fix. CERT-Bund lists Linux and UNIX as the affected operating systems. The companion critical advisory GHSA-2872-rg44-j9gx, a safeEjs notifier sandbox escape, is fixed in 7.260811.0.
Exposure context
ZoomEye returned 1046 instances for app="OpenCTI" and 0 for vul.cve="CVE-2026-76822" at the time of writing. The product count covers internet-facing deployments of any version and leaves out internal ones, and the CVE count is zero because an authorization flaw leaves nothing visible to an external scanner.
Remediation and mitigations
Upgrade to 7.260701.0 or later, and prefer 7.260811.0 for full coverage of the advisory batch. Then restore provenance: audit case creation against role assignments, remove or flag cases that no authorised role produced, and restrict authentication to principals the workflow genuinely needs. Add a regression test that requires a capability decorator on every case mutation so the gap cannot re-enter through a later change.
References
- GitHub Security Advisory GHSA-w45v-76pj-xggm: https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-w45v-76pj-xggm
- CERT-Bund advisory WID-SEC-2026-3563: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3563
- GitHub Security Advisory GHSA-2872-rg44-j9gx: https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-2872-rg44-j9gx
- OpenCTI deployment documentation: https://docs.opencti.io/latest/deployment/overview/
Top comments (0)