/Vulnerability Library

OpenCTI < 6.9.13 - Authentication Bypass via User Impersonation

CVE-2026-27960
Verified

Description

OpenCTI < 6.9.13 allows authentication bypass by supplying a Bearer token set to the admin user's internal_id UUID instead of a valid JWT. The default admin internal_id (88ec0c6a-13ce-5e39-b486-354fe4a7084f) grants full admin access to the GraphQL API, effectively bypassing all authentication.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

opencti

Published Date

September 15, 2026

Template Author

dhiyaneshdk

CVE-2026-27960.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27960
CWE ID:
cwe-287

References

https://nvd.nist.gov/vuln/detail/CVE-2026-27960https://www.pruva.dev/reproductions/REPRO-2026-00314https://www.pruva.dev/reproductions/REPRO-2026-00331

Remediation Steps

Upgrade OpenCTI to version 6.9.13 or later.