DEV Community

StarkMan
StarkMan

Posted on

OpenCTI Case Creation Flaw CVE-2026-76822: A Permission Model Postmortem

OpenCTI Case Creation Flaw CVE-2026-76822: A Permission Model Postmortem

Vulnerability overview

CVE-2026-76822 is a moderate authorization flaw in OpenCTI, the open-source cyber threat intelligence platform maintained by Filigran. GitHub advisory GHSA-w45v-76pj-xggm scores it 4.3, credits SalusCyber1, and carries the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. CERT-Bund records it as WID-SEC-2026-3563. The interesting question is how three resolvers ended up outside the permission model.

How the authorization gap works

OpenCTI applies two decorators that developers must combine. @auth establishes that the caller holds a session. Capability decorators, referencing permissions such as the settings and knowledge scopes, establish that the caller may perform the action. The case workflow mutations caseIncidentAdd, caseRfiAdd and caseRftAdd carried @auth alone. Their authorization collapsed into authentication.

Exploitation conditions

Network vector, low complexity, low privileges, no user interaction. Exploitation needs only a valid session, and a reader account satisfies that requirement. The calls are ordinary GraphQL writes rather than exploit payloads, so nothing in the request stream stands out as hostile.

Impact

The advisory records integrity loss with confidentiality and availability unaffected. The operational reading is that unauthorized case objects persist in the platform and mix with genuine analyst output. Rebuilding trust in the case queue, incidents, requests for information and requests for takedown, takes an authorship audit rather than a log search.

Affected products and scope

OpenCTI below 7.260701.0 is vulnerable and 7.260701.0 is the fixed release. CERT-Bund lists Linux and UNIX as the affected operating systems. A critical companion advisory, GHSA-2872-rg44-j9gx, describes a sandbox escape in the safeEjs notifier template and is fixed in 7.260811.0.

Exposure context

ZoomEye returned 1046 internet-facing instances for app="OpenCTI" and 0 for vul.cve="CVE-2026-76822". The product fingerprint count includes patched and unpatched systems alike and excludes internal deployments; the CVE query returns zero because an authorization gap produces no externally visible marker.

Remediation and mitigations

Upgrade to 7.260701.0 or later, and prefer 7.260811.0 to close the critical companion advisory in the same maintenance window. The structural lesson is to enforce the pairing of @auth with a capability decorator in review and in tests, because the failure mode here is a missing line rather than a flawed algorithm.

References

Top comments (0)