CVE-2026-21887Disclosure(citeum / opencti)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-supplied URLs without validation and uses the Axios HTTP client with its default configuration (allowAbsoluteUrls: true). This allows attackers to craft requests to arbitrary endpoints, including internal services, because Axios will accept and process absolute URLs. This results in a semi-blind SSRF, as responses may not be fully visible but can still impact internal systems. This vulnerability is fixed in 6.8.16.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencti

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
opencti

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-06-22: 1Technical Details · 2026-03-12: 103-1206-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure1General1
2026-06-221
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenCTI, Server-Side Request Forgery (SSRF), #CVE-2026-21887 (High) -DC-Jun2026-545 https://dailycve.com/opencti-server-side-request-forgery-ssrf-cve-2026-21887-high-dc-jun2026-545/

    Post summary

    The tweet announces the discovery of a new high‑severity SSRF vulnerability (CVE‑2026‑21887) affecting OpenCTI, with no additional details or mitigation information provided.

    0000055
    216 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-21887 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature ac… https://www.cve.org/CVERecord?id=CVE-2026-21887

    Post summary

    The post references CVE‑2026‑21887 for OpenCTI’s data ingestion feature, linking to the CVE record, but provides no additional technical, exploit, or mitigation information.

    00000161
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21887 Server-Side Request Forgery (SSRF) in OpenCTI Platform Before 6.8.16 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21887

    Post summary

    The post discloses an SSRF vulnerability (CVE‑2026‑21887) affecting OpenCTI Platform before version 6.8.16, with no PoC or exploitation details shared.

    0000018
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciteumopencti---

Explore more