OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable body data. The content of the body field isn't appropriately sanitized when being rendered. Does require user interaction but could be exploited by someone sharing stix or any of the ingester. This could lead to CSRF and then large scale session theft. Version 7.260227.0 contains a fix.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Citeum
Citeum opencti |
|
| CPEs | cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Citeum
Citeum opencti |
|
| Metrics |
cvssV3_1
|
Wed, 03 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opencti-platform
Opencti-platform opencti |
|
| Vendors & Products |
Opencti-platform
Opencti-platform opencti |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable body data. The content of the body field isn't appropriately sanitized when being rendered. Does require user interaction but could be exploited by someone sharing stix or any of the ingester. This could lead to CSRF and then large scale session theft. Version 7.260227.0 contains a fix. | |
| Title | OpenCTI has XSS in the rendering of email-message observable body data | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-02T21:28:59.375Z
Updated: 2026-06-03T14:23:27.028Z
Reserved: 2026-04-01T18:48:58.937Z
Link: CVE-2026-35212
Updated: 2026-06-03T14:23:14.679Z
Status : Analyzed
Published: 2026-06-02T22:16:16.727
Modified: 2026-06-05T13:07:04.890
Link: CVE-2026-35212
No data.