Opencti-platform

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-35211

    OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS

    Last Modified: Jul 10, 2026
    Published: Jul 08, 2026

    CVE-2026-35210

    OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection

    Last Modified: Jul 09, 2026
    Published: Jul 08, 2026

    CVE-2026-35212

    OpenCTI has XSS in the rendering of email-message observable body data

    Last Modified: Jun 05, 2026
    Published: Jun 02, 2026

    CVE-2026-44730

    OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd

    Last Modified: May 28, 2026
    Published: May 26, 2026

    CVE-2026-27960

    OpenCTI privilege escalation and unauthenticated access via default admin account

    Last Modified: May 12, 2026
    Published: May 05, 2026
    Items Per Page