Arbitrary Deletion Vulnerability in OpenCTI Cyber Threat Intelligence Platform
CVE-2025-61781
7.1HIGH
What is CVE-2025-61781?
The OpenCTI platform, used for managing cyber threat intelligence, has a vulnerability where the GraphQL mutation 'WorkspacePopoverDeletionMutation' permits unauthorized deletion of vital resources such as dashboards and investigation cases. This flaw arises from a lack of proper authorization checks before executing deletion requests. An attacker can exploit this by providing the UUID of an object belonging to another user, leading to potential loss of critical workspace data. The issue has been resolved in version 6.8.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opencti < 6.8.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
