An attacker can exploit this by supplying an active UUID of another user. Since the API does not validate whether the requester owns the resource, the mutation executes successfully, resulting in unauthorized deletion of the entire workspace. Version 6.8.1 fixes the issue.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opencti-platform
Opencti-platform opencti |
|
| Vendors & Products |
Opencti-platform
Opencti-platform opencti |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" allows users to delete workspace-related objects such as dashboards and investigation cases. However, the mutation lacks proper authorization checks to verify ownership of the targeted resources. An attacker can exploit this by supplying an active UUID of another user. Since the API does not validate whether the requester owns the resource, the mutation executes successfully, resulting in unauthorized deletion of the entire workspace. Version 6.8.1 fixes the issue. | |
| Title | GraphQL IDOR allows authenticated user to delete workspace content of other users | |
| Weaknesses | CWE-285 CWE-566 CWE-915 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-05T19:43:45.569Z
Reserved: 2025-09-30T19:43:49.902Z
Link: CVE-2025-61781
Updated: 2026-01-05T19:43:40.416Z
Status : Received
Published: 2026-01-05T18:15:44.077
Modified: 2026-01-05T18:15:44.077
Link: CVE-2025-61781
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:16:36Z