CVE-2026-39980Disclosure(citeum / opencti)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch citeum opencti systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaScript in the context of the OpenCTI platform process during notifier template execution. This vulnerability is fixed in 6.9.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencti

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
opencti

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-22: 1Mentions · 2026-04-28: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-09: 2Technical Details · 2026-04-09: 3Technical Details · 2026-04-22: 1Technical Details · 2026-04-28: 1Technical Details · 2026-07-29: 104-0904-2204-2807-29
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure2Patch1
2026-04-221
Disclosure1
2026-04-281
Disclosure1
2026-07-291
Disclosure1
Full discourse6 posts
  • kmkz@kmkz_security
    Disclosure

    Aaand chained with the CVE-2026-39980 (no public sploit... at least since now) -> preauth root rce with 2 vulns on OpenCTI instance . Another day, another pwnage

    Post summary

    The text highlights CVE-2026-39980 as a pre‑authentication root RCE on OpenCTI, but notes that no public exploit or patch is currently available.

    101746.9K
    19.8K followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-39980: Critical RCE Flaw Found in OpenCTI Platform https://thecybrdef.com/cve-2026-39980-opencti-rce-vulnerability/ #CVE202639980 #OpenCTI #CyberSecurity*

    Post summary

    The snippet announces a critical remote code execution vulnerability (CVE-2026-39980) in the OpenCTI platform, but does not include details on PoC, exploit code, active exploitation, or remediation.

    0000075
    7 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-39980: Critical RCE Flaw Found in OpenCTI Platform https://thecybrdef.com/cve-2026-39980-opencti-rce-vulnerability/ #CVE202639980 #OpenCTI #CyberSecurity

    Post summary

    The post announces CVE-2026-39980, a critical remote code execution flaw in OpenCTI, without providing proof of concept, exploitation details, patch information, or evidence of active attacks.

    0000076
    6 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39980: CRITICAL] OpenCTI platform fixed a critical vulnerability in version 6.9.5 where unsafe EJS templates could allow arbitrary JavaScript execution by users with Manage customization capability...#cve,CVE-2026-39980,#cybersecurity https://cvefind.com/CVE-2026-39980

    Post summary

    OpenCTI released a fix for CVE-2026-39980, addressing unsafe EJS templates that could enable arbitrary JavaScript execution.

    0000045
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39980 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJ… https://www.cve.org/CVERecord?id=CVE-2026-39980

    Post summary

    CVE-2026-39980 is a recent vulnerability in OpenCTI’s safeEjs.ts module, affecting versions before 6.9.5 due to improper sanitization. No exploit, PoC, or detailed patch information is provided beyond the indication that version 6.9.5 contains a fix.

    00000110
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39980: OpenCTI affected by RCE via noti... OpenCTI's EJS template sanitization bypass lets high-privs admins execute arbitrary JS server-side—classic template inj... https://zerodaysignal.com/vulnerability/CVE-2026-39980 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑39980 is an RCE vulnerability in OpenCTI caused by EJS template sanitization bypass, enabling high‑privileged admins to run arbitrary server‑side JavaScript; PoC details appear to be available via the provided link.

    0000067
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciteumopencti---

Explore more