OpenCTI < 6.9.13 - Authentication Bypass via User Impersonation
CVE-2026-27960
Verified
Description
OpenCTI < 6.9.13 allows authentication bypass by supplying a Bearer token set to the admin user's internal_id UUID instead of a valid JWT. The default admin internal_id (88ec0c6a-13ce-5e39-b486-354fe4a7084f) grants full admin access to the GraphQL API, effectively bypassing all authentication.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Affected Product
opencti
Published Date
September 15, 2026
Template Author
dhiyaneshdk
CVE-2026-27960.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27960
CWE ID:
cwe-287
Remediation Steps
Upgrade OpenCTI to version 6.9.13 or later.