CVE-2026-35211: OpenCTI GraphQL API Denial of Service via Unsanitized Painless Scripts
OpenCTI, an open-source cyber threat intelligence platform, contains a vulnerability in its GraphQL API that allows authenticated users to inject computationally expensive script code. Any user with knowledge management permissions can craft malicious search queries that consume excessive CPU resources on the Elasticsearch backend, degrading performance for all users and potentially causing service unavailability. This is a denial-of-service vulnerability that requires valid credentials but no special privileges beyond standard KNOWLEDGE capability access.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-863, CWE-94
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-08 / 2026-07-13
NVD description (verbatim)
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator in its FilterOperator enum that allows any authenticated user with the KNOWLEDGE capability to pass user-supplied Elasticsearch Painless script values directly into search queries without validation or sanitization, allowing computationally expensive scripts to consume cluster CPU resources and degrade or deny service for all users. This issue is fixed in version 7.260401.0.
4 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in OpenCTI versions prior to 7.260401.0 within the GraphQL API's FilterOperator enum. The script filter operator accepts unsanitized Elasticsearch Painless script values directly from authenticated requests. An attacker with KNOWLEDGE capability can pass arbitrary Painless expressions that execute expensive computational operations on the Elasticsearch cluster, consuming CPU and degrading cluster performance. The vulnerability stems from insufficient input validation and sanitization of user-supplied script parameters before they reach the Elasticsearch query engine. CWE-863 (Incorrect Authorization) and CWE-94 (Improper Control of Generation of Code) are the contributing weaknesses.
Business impact
Organizations running OpenCTI as their threat intelligence platform face potential service disruptions during normal operations. An authenticated insider or compromised account holder can degrade or deny access to threat intelligence data for the entire organization without sophisticated tooling. This impacts incident response workflows, threat hunting capabilities, and any downstream systems relying on OpenCTI API availability. The impact is operational rather than confidential—no data exposure or integrity compromise—but availability loss of a central intelligence system can cascade across security operations.
Affected systems
OpenCTI versions prior to 7.260401.0 are affected. This includes all Citeum OpenCTI deployments running older releases. The vulnerability requires the attacker to possess valid credentials and the KNOWLEDGE capability, limiting the attack surface to authenticated users within the organization or those with compromised accounts.
Exploitability
Exploitation requires valid authentication credentials and the KNOWLEDGE capability within OpenCTI. No network or authentication bypass is needed—the vulnerability is accessible through the standard GraphQL API endpoint. Crafting a malicious script requires understanding Elasticsearch Painless syntax, but proof-of-concept payloads are conceptually straightforward. The CVSS score of 6.5 (MEDIUM) reflects the authentication requirement balanced against the high availability impact. This vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
Remediation
Upgrade OpenCTI to version 7.260401.0 or later, which implements validation and sanitization of script filter values. Organizations unable to patch immediately should restrict KNOWLEDGE capability permissions to trusted users only and monitor Elasticsearch cluster metrics for unusual CPU spikes that may indicate exploitation attempts.
Patch guidance
Apply the update to OpenCTI 7.260401.0 or later as soon as possible. Verify the update is available through your deployment channel (container images, package managers, or source builds depending on your deployment method). Test the upgrade in a non-production environment first to ensure compatibility with your threat intelligence workflows and any custom integrations. Review user access and KNOWLEDGE capability assignments during the patching window.
Detection guidance
Monitor Elasticsearch cluster CPU utilization and query latency for anomalies, particularly spikes correlated with GraphQL API requests. Enable query logging in Elasticsearch to capture slow or resource-intensive Painless script executions. Check GraphQL API audit logs for unusual script filter parameters in queries from unexpected users or at atypical times. Baseline normal query patterns first to establish detection thresholds. Network-based detection is difficult without decrypting HTTPS traffic; focus on application and infrastructure logs.
Why prioritize this
This vulnerability should be prioritized for patching within 30 days. While authentication is required, threat intelligence platforms are often access-rich environments where multiple users hold elevated permissions. The potential for insider threat or credential compromise is relevant in many organizations. The availability impact directly affects security operations, making it more urgent than low-impact vulnerabilities, though lower priority than critical remote code execution or confidentiality breaches.
Risk score, explained
CVSS 6.5 (MEDIUM) accurately reflects this vulnerability's profile. The authentication requirement significantly reduces the attack surface (PR:L), preventing unauthenticated exploitation. However, the high availability impact (A:H) is not mitigated by the authentication barrier since authorized users can exploit it. No confidentiality or integrity impact exists. This is a classic insider/compromised-account denial-of-service scenario with operational but not strategic consequences.
Frequently asked questions
Can this vulnerability be exploited without valid OpenCTI credentials?
No. The vulnerability requires authentication and the KNOWLEDGE capability within OpenCTI. Unauthenticated users cannot access the vulnerable GraphQL API endpoint. This limits exploitation to insider threats or attackers who have compromised valid user accounts.
What is the difference between this vulnerability and a typical denial-of-service attack?
Typical DoS attacks are external and volumetric. This vulnerability allows an authenticated user to cause severe resource exhaustion with minimal crafted requests, making it an application-layer DoS. A single malicious script can consume significant CPU, affecting all users immediately without the attacker needing to send high volumes of traffic.
Is there a workaround if we cannot patch immediately?
A complete workaround does not exist without patching. Mitigation measures include restricting KNOWLEDGE capability assignments to only essential users, implementing network-level access controls to the GraphQL API, and monitoring Elasticsearch cluster metrics for exploitation attempts. However, determined insiders with KNOWLEDGE access can still attempt exploitation.
Does this vulnerability expose our threat intelligence data?
No. The vulnerability is a denial-of-service issue targeting availability, not a data confidentiality breach. Your threat intelligence data is not exposed, exfiltrated, or modified. The concern is service interruption and performance degradation, not data compromise.
This analysis is based on publicly disclosed vulnerability information current as of the publication date. Organizations must verify patch availability and compatibility against their specific OpenCTI deployment version and configuration. CVSS scoring reflects the general vulnerability profile; organizational risk varies based on access controls, user privilege assignments, and monitoring capabilities. For authoritative patching guidance, consult Citeum's official security advisories and release notes. This explainer is for informational purposes and does not constitute a security audit or guarantee of vulnerability remediation success. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35210HIGHOpenCTI Authorization Bypass via Synchronized-Upsert Header
- CVE-2026-0414MEDIUMNETGEAR RBE970 Admin Input Validation Flaw
- CVE-2026-10153MEDIUMCross-Site Scripting in westboy CicadasCMS Search Function
- CVE-2026-10173MEDIUMCross-Site Scripting in Orthanc Explorer 2 – Patch Guidance & Detection
- CVE-2026-10175MEDIUMCode Injection in Aider-AI Aider 0.86.3 – Exploit Available
- CVE-2026-10211MEDIUMAstrBot 4.23.6 Path Normalization Authorization Bypass
- CVE-2026-10289MEDIUMXSS Vulnerability in Hotel and Tourism Reservation System 1.0
- CVE-2026-10301MEDIUMReflected XSS in itsourcecode Fees Management System 1.0 – Exploit Public