CVE-2026-35212

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-message observable body data. The content of the body field isn't appropriately sanitized when being rendered. Does require user interaction but could be exploited by someone sharing stix or any of the ingester. This could lead to CSRF and then large scale session theft. Version 7.260227.0 contains a fix.
Configurations

Configuration 1 (hide)

cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) OpenCTI es una plataforma de código abierto para gestionar el conocimiento y los observables de inteligencia de ciberamenazas. Las versiones anteriores a la 7.260227.0 son vulnerables a XSS en la representación de los datos del cuerpo de los observables de mensajes de correo electrónico. El contenido del campo del cuerpo no se sanea adecuadamente al ser representado. Requiere interacción del usuario, pero podría ser explotado por alguien que comparta stix o cualquiera de los ingester. Esto podría conducir a CSRF y luego a un robo de sesión a gran escala. La versión 7.260227.0 contiene una corrección.

05 Jun 2026, 13:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Citeum opencti
Citeum
References () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-rg6r-x26x-63vq - () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-rg6r-x26x-63vq - Vendor Advisory
CPE cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*

02 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 22:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-35212

Mitre link : CVE-2026-35212

CVE.ORG link : CVE-2026-35212


JSON object : View

Products Affected

citeum

  • opencti
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')