CVE-2026-27960General(citeum / opencti)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch citeum opencti systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencti

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • General: 6 classified signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 4 mentions (2026-05-11); latest day: 1
  • 15 total mentions across 8 days

Affected systems

Vendors
Products
opencti

Deep dive

Activity timeline15 mentions / 8d
01234Mentions · 2026-05-05: 2Mentions · 2026-05-06: 2Mentions · 2026-05-07: 2Mentions · 2026-05-11: 4Mentions · 2026-05-13: 1Mentions · 2026-09-16: 1Mentions · 2026-09-21: 2Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-09-21: 1Active Exploitation · 2026-09-21: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 2Technical Details · 2026-05-11: 3Technical Details · 2026-05-13: 1Technical Details · 2026-09-16: 105-0505-0605-0705-1105-1309-1609-2110-06
Signal classification5 categories
General
642.9%
Disclosure
535.7%
Patch
17.1%
PoC
17.1%
Active Exploitation
17.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1General1
2026-05-062
Disclosure1Patch1
2026-05-072
Disclosure2
2026-05-114
General4
2026-05-131
Disclosure1
2026-09-161
PoC1
2026-09-212
Active Exploitation1General1
Full discourse15 posts
  • Previdian@PrevidianCyber
    Active Exploitation

    Yesterday we saw first exploitation attempt for OpenCTI (CVE-2026-27960) in our honeypot network using the public Nuclei template. Attacker IP located in Yemen (109.200.170[.]0) Link in comments 👇 https://t.co/nBT5xu8YjM

    Post summary

    The tweet reports an observed exploitation attempt against OpenCTI CVE-2026-27960 in a honeypot using a public Nuclei template, with an attacker IP, making active exploitation the core message.

    211821.2K
    166 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-27960 - critical 🚨 OpenCTI < 6.9.13 - Authentication Bypass via User Impersonation > OpenCTI < 6.9.13 allows authentication bypass by supplying a Bearer token set to the ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27960 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-27960) affecting OpenCTI versions prior to 6.9.13 is disclosed, with a proof‑of‑concept (including a Nuclei template) made available via a shared library link.

    02062628
    1.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    OpenCTIでCritical扱いの脆弱性。 認証されていない第三者が既存の任意のユーザー(管理者含む)でAPIでのクエリ実行が可能に。 CVE-2026-27960 Priviledge escalation and unauthenticated access using default admin https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-6vvv-vmfr-xhrx

    Post summary

    An advisory alerts that CVE‑2026‑27960 allows unauthenticated users to execute API queries as any existing user, including administrators, on OpenCTI.

    00041562
    6.9K followersView on X
  • Luis Silva@luismssilva

    It always amazes me, when they discover vulnerabilities in software that's supposed to protect our infrastructure from cyberattacks. This is totally normal btw, but we do see this a lot. For example this one: CVE-2026-27960, all the recent ones regarding Citrix NetScaler GW...

    1001075
    96 followersView on X
  • Previdian@PrevidianCyber
    General

    https://previdian.com/CVE-2026-27960

    Post summary

    The text consists solely of a URL linking to a CVE page, providing no further information.

    01010110
    116 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-27960: OpenCTI unauthenticated API impersonation - What It Means for Your Business and How to Respond https://hubs.li/Q04gr-CB0

    Post summary

    The text announces the CVE-2026-27960 vulnerability involving unauthenticated API impersonation in OpenCTI, without providing any PoC, exploit code, patch, or evidence of active exploitation.

    0000039
    30 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-27960-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided excerpt offers only a URL and generic hashtags without substantive information about the vulnerability, its exploitation status, or mitigations.

    0000031
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-27960 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry notes vulnerability CVE-2026-27960 as critical with a high CVSS score, but offers no proof‑of‑concept, exploit code, or remediation details.

    0000039
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-27960 (CVSS 9.8) — multiple products. CVE: CVE-2026-27960 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post is a basic critical advisory for CVE-2026-27960, noting its CVSS 9.8 score and severity but providing no further technical or exploitation details.

    0000032
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-27960 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables.

    Post summary

    The text announces CVE-2026-27960 as a critical vulnerability, providing its CVSS score and severity, but does not mention a PoC, exploit tool, or mitigation.

    0000065
    197 followersView on X
  • Polsia@polsia
    Disclosure

    CVE-2026-27960 (OpenCTI privilege escalation, CVSS 9.8). Unauthenticated attackers query your threat intel platform as admin. Versions 6.6.0-6.9.12 affected. 48 hours, your SOC hasn't heard. ThreatForge catches these. https://threatforge-l929.polsia.app

    Post summary

    The post announces CVE‑2026‑27960, a high‑severity privilege escalation flaw in OpenCTI (CVSS 9.8) affecting versions 6.6.0‑6.9.12, and notes that it is detectable via ThreatForge, with no PoC, exploit, or patch information provided.

    0000067
    15.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Privilege Escalation vulnerability discovered in #OpenCTI. #CVE-2026-27960 (CVSS 9.8) allows unauthenticated attackers to query the API as any existing user, including admin. More info: https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-6vvv-vmfr-xhrx #Patch #Patch #Patch

    Post summary

    Critical privilege escalation discovered in OpenCTI (CVE-2026-27960) with CVSS 9.8; patch is available as indicated by the advisory link and repeated #Patch tags.

    00000238
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27960 Unauthenticated Privilege Escalation in OpenCTI 6.6.0 Thr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27960 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE‑2026‑27960, describing it as an unauthenticated privilege escalation in OpenCTI 6.6.0, and directs readers to a vulnerability details page, but provides no PoC, exploit code, or patch information.

    0000078
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    General

    🚨 CRITICAL — CVE-2026-27960 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-27960 #Intel #CyberSecurity #InfoSec

    Post summary

    The post announces a critical vulnerability (CVE-2026-27960) affecting OpenCTI 6.6.0 with a CVSS score of 9.8 and notes no patch is yet available, directing readers to a full analysis link for details.

    00000105
    469 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27960 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation… https://www.cve.org/CVERecord?id=CVE-2026-27960

    Post summary

    The post announces a privilege‑escalation vulnerability (CVE‑2026‑27960) affecting OpenCTI 6.6.0‑6.9.12, without providing PoC, exploit, or patch details.

    00000162
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciteumopencti---

Explore more