Arbitrary Deletion Vulnerability in OpenCTI Cyber Threat Intelligence Platform
CVE-2025-61781
7.1HIGH
What is CVE-2025-61781?
The OpenCTI platform, used for managing cyber threat intelligence, has a vulnerability where the GraphQL mutation 'WorkspacePopoverDeletionMutation' permits unauthorized deletion of vital resources such as dashboards and investigation cases. This flaw arises from a lack of proper authorization checks before executing deletion requests. An attacker can exploit this by providing the UUID of an object belonging to another user, leading to potential loss of critical workspace data. The issue has been resolved in version 6.8.1.
Affected Version(s)
opencti < 6.8.1
