CVE-2026-44730: OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd
Summary An organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization.
Impact Full platform access, access to sensitive or proprietary information.
Other sources
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization. This is due to incorrect ACL on userEdit relationAdd. This vulnerability is fixed in 6.9.7.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pyctito a version that resolves this vulnerability.Fixed in 6.9.7 - Upgrade
Upgrade
OpenCTIto a version that resolves this vulnerability.Fixed in 6.9.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44730?
CVE-2026-44730 has a severity rating of high, with a score of 7.2.
How do I fix CVE-2026-44730?
To fix CVE-2026-44730, ensure that your ACLs are correctly configured to prevent organization admins from escalating privileges through the GraphQL API.
What systems are affected by CVE-2026-44730?
CVE-2026-44730 affects OpenCTI and related software platforms like Citeum Opencti and pip/pycti.
What are the potential impacts of CVE-2026-44730?
The potential impacts of CVE-2026-44730 include full platform access and exposure to sensitive data.
Who can exploit CVE-2026-44730?
CVE-2026-44730 can be exploited by organization admins who can add users from different organizations with higher privileges.