Description
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0, the synchronizerFetch GraphQL query called fetchRemoteStreams after checking only that a remote stream URL used HTTP or HTTPS. The backend did not apply the ingestion deny list or reject private, loopback, and link-local destinations, allowing an authenticated account with the INGESTION capability to make OpenCTI request internal services and cloud metadata endpoints. Returned connection errors could distinguish open HTTP ports, open non-HTTP ports, and closed ports, enabling internal network scanning, while compatible endpoint responses could disclose internal data. This issue is fixed in version 7.260701.0.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery enabling internal network discovery and data exposure
Action: Immediate Patch
AI Analysis

Impact

OpenCTI’s synchronizerFetch GraphQL query allowed any authenticated user with the INGESTION role to fetch remote streams from arbitrary HTTP or HTTPS URLs without validating the destination. The lack of an ingestion deny list and failure to reject private or loopback addresses introduced a server‑side request forgery flaw described by CWE‑918. This flaw can lead to internal network scans, disclose open ports, and expose sensitive internal services or cloud metadata. The data from the upstream endpoints can be accessed by the OpenCTI platform or downstream systems.

Affected Systems

The vulnerability affects the OpenCTI platform (7.260701.0). Any deployment using or earlier than that release is susceptible, regardless of the operating system or hosting environment.

Risk and Exploitability

The vulnerability has a CVSS score of 7.7 and an EPSS of less than 1%, indicating a high severity but a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack path requires an authenticated account with INGESTION capability and involves sending a malicious GraphQL query that instructs the server to retrieve a remote stream from a crafted internal URL. Because the server performs no destination validation, the attacker can probe internal services, determine port states, and potentially exfiltrate data. Preventing exposure thus hinges on applying the vendor fix or mitigating the allowed capabilities.

Generated by OpenCVE AI on September 20, 2026 at 11:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenCTI version 7.260701.0 or newer.
  • Revoke the INGESTION capability from all users until the upgrade is applied.
  • Restrict the OpenCTI server’s outbound traffic to privileged IPs or block internal IP ranges using firewall rules.

Generated by OpenCVE AI on September 20, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Opencti-platform
Opencti-platform opencti
Vendors & Products Opencti-platform
Opencti-platform opencti

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0, the synchronizerFetch GraphQL query called fetchRemoteStreams after checking only that a remote stream URL used HTTP or HTTPS. The backend did not apply the ingestion deny list or reject private, loopback, and link-local destinations, allowing an authenticated account with the INGESTION capability to make OpenCTI request internal services and cloud metadata endpoints. Returned connection errors could distinguish open HTTP ports, open non-HTTP ports, and closed ports, enabling internal network scanning, while compatible endpoint responses could disclose internal data. This issue is fixed in version 7.260701.0.
Title OpenCTI: Synchronizer SSRF: stream fetch has no URL validation
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Opencti-platform Opencti
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T19:23:48.304Z

Reserved: 2026-08-19T19:52:28.214Z

Link: CVE-2026-76820

cve-icon Vulnrichment

Updated: 2026-09-16T19:23:40.256Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:57.127

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-76820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)