OpenCTI Platform's Data Ingestion Vulnerability Exposes Internal Services
CVE-2026-21887

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
12 March 2026

What is CVE-2026-21887?

The OpenCTI platform's data ingestion feature poses a security risk by accepting unvalidated user-supplied URLs. This flaw allows attackers to send requests to arbitrary endpoints, including internal services, by leveraging the Axios HTTP client’s default configuration, which permits absolute URLs. Although the responses to these requests may not be fully visible to the attacker, they can still adversely affect internal systems. A patch has been released in version 6.8.16 to rectify this security issue.

Affected Version(s)

opencti < 6.8.16

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.