CVE-2026-76820: OpenCTI: Synchronizer SSRF: stream fetch has no URL validation

Published Sep 15, 2026
·
Updated

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0, the synchronizerFetch GraphQL query called fetchRemoteStreams after checking only that a remote stream URL used HTTP or HTTPS. The backend did not apply the ingestion deny list or reject private, loopback, and link-local destinations, allowing an authenticated account with the INGESTION capability to make OpenCTI request internal services and cloud metadata endpoints. Returned connection errors could distinguish open HTTP ports, open non-HTTP ports, and closed ports, enabling internal network scanning, while compatible endpoint responses could disclose internal data. This issue is fixed in version 7.260701.0.

Affected Software

1 affected component
OpenCTI OpenCTI<7.260701.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenCTI synchronizer to a version that resolves this vulnerability.

    Fixed in 7.260701.0

Event History

Sep 15, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated OpenCTI account with the INGESTION capability can exploit it. The attacker must be able to invoke the synchronizerFetch GraphQL query and provide a remote stream URL.

2

Which deployments are affected?

OpenCTI versions prior to 7.260701.0 are affected. The vulnerable backend accepted HTTP and HTTPS URLs without applying the ingestion deny list or blocking private, loopback, and link-local destinations.

3

What can an attacker do through the vulnerable fetch operation?

An attacker can cause the OpenCTI backend to send requests to internal services and cloud metadata endpoints. Response behavior can also be used to distinguish open HTTP ports, open non-HTTP ports, and closed ports for internal network scanning.

4

How can the risk be reduced before upgrading?

Restrict the INGESTION capability to trusted accounts, since that capability is required to exploit the issue. Upgrade to OpenCTI 7.260701.0, which fixes the URL validation issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203