DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Auditing OpenCTI Case Creation After CVE-2026-76822

Auditing OpenCTI Case Creation After CVE-2026-76822

Vulnerability overview

CVE-2026-76822 is a moderate authorization bug in OpenCTI, the open-source threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm rates it 4.3 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N and credits SalusCyber1. CERT-Bund carries the same issue in WID-SEC-2026-3563. The impact profile, integrity only and no confidentiality or availability loss, shapes the follow-up work after upgrading.

How the authorization gap works

The vendor description states that the GraphQL mutations caseIncidentAdd, caseRfiAdd and caseRftAdd are protected by @auth alone. Authentication establishes identity; authorization establishes permission, and in OpenCTI the second layer is expressed through capability checks such as the settings and knowledge permissions. Those three mutations skipped the capability layer, so any authenticated user could create cases regardless of role.

Exploitation conditions

Reachability is straightforward: network vector, low complexity, low privileges, no user interaction. An attacker with any account, reader level included, can send the mutations to the API. Because the writes are ordinary platform operations rather than malformed input, nothing about the request looks like an exploit at the transport layer.

Impact

Only integrity is affected, which means the artifacts of abuse persist in the data rather than in logs. Unauthorized cases, incidents, requests for information and requests for takedown, mix with legitimate analyst output. Triage queues grow, case counters drift, and reporting can cite entries that no authorized analyst produced. Reconstructing which cases were legitimate becomes the main post-incident task.

Affected products and scope

OpenCTI below 7.260701.0 is affected; 7.260701.0 is the patched release. CERT-Bund lists Linux and UNIX as the affected operating systems. The bug lives in the GraphQL layer, so the deployment method does not change the vulnerable set.

Exposure context

ZoomEye reports 1046 instances matching app="OpenCTI" and 0 matching vul.cve="CVE-2026-76822". Treat the first as fingerprint-level exposure that includes already patched systems and excludes internal deployments, and the second as an expected blank for a flaw with no external signature.

Remediation and mitigations

Upgrade to 7.260701.0 or later, and prefer 7.260811.0 to also cover the critical safeEjs advisory GHSA-2872-rg44-j9gx from the same batch. Then audit: compare case creation events against the roles authorized to create them, review reader accounts for unexpected activity, and tighten capability assignments so that the next gap of this kind has a narrower blast radius. Keep the audit evidence, since integrity-only incidents are proven from platform data rather than from network telemetry.

References

Top comments (0)