OpenCTI Platform's Data Ingestion Vulnerability Exposes Internal Services
CVE-2026-21887
7.7HIGH
What is CVE-2026-21887?
The OpenCTI platform's data ingestion feature poses a security risk by accepting unvalidated user-supplied URLs. This flaw allows attackers to send requests to arbitrary endpoints, including internal services, by leveraging the Axios HTTP client’s default configuration, which permits absolute URLs. Although the responses to these requests may not be fully visible to the attacker, they can still adversely affect internal systems. A patch has been released in version 6.8.16 to rectify this security issue.
Affected Version(s)
opencti < 6.8.16
