PT-2026-56601 · Opencti · Opencti

CVE-2026-35210

·

Published

2026-07-08

·

Updated

2026-07-11

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenCTI versions prior to 7.260326.0
Description An authorization bypass allows authenticated users with KNOWLEDGE KNUPDATE permission to circumvent Confidence Level validation and Object Marking restrictions. This is achieved by injecting the synchronized-upsert: true HTTP header. Attackers can use this method to downgrade confidence levels, remove security markings like TLP:RED, manipulate relationships, and modify STIX object types, including Indicators, ThreatActors, Malware, and Reports.
Recommendations Update to version 7.260326.0.

Exploit

Fix

Incorrect Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35210
GHSA-36FR-4M54-94MJ
PYSEC-2026-3445

Affected Products

Opencti