AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-35211

MEDIUM · CVSS 6.5 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The OpenCTI GraphQL API prior to version 7.260401.0 is vulnerable, allowing authenticated users with the KNOWLEDGE capability to execute unvalidated Elasticsearch Painless scripts, which can lead to excessive CPU consumption and potential denial of service for all users. Organizations utilizing OpenCTI should prioritize upgrading to version 7.260401.0 to mitigate this risk and ensure the stability of their threat intelligence operations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-35211
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%

Original NVD Description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator in its FilterOperator enum that allows any authenticated user with the KNOWLEDGE capability to pass user-supplied Elasticsearch Painless script values directly into search queries without validation or sanitization, allowing computationally expensive scripts to consume cluster CPU resources and degrade or deny service for all users. This issue is fixed in version 7.260401.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)