CVE-2026-76820
Awaiting Analysis Awaiting Analysis - Queue

OpenCTI Remote Stream Server-Side Request Forgery

Vulnerability report for CVE-2026-76820, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0, the synchronizerFetch GraphQL query called fetchRemoteStreams after checking only that a remote stream URL used HTTP or HTTPS. The backend did not apply the ingestion deny list or reject private, loopback, and link-local destinations, allowing an authenticated account with the INGESTION capability to make OpenCTI request internal services and cloud metadata endpoints. Returned connection errors could distinguish open HTTP ports, open non-HTTP ports, and closed ports, enabling internal network scanning, while compatible endpoint responses could disclose internal data. This issue is fixed in version 7.260701.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opencti opencti 7.260701.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in OpenCTI versions before 7.260701.0. It allows authenticated users with ingestion privileges to bypass URL validation and make the OpenCTI backend issue arbitrary HTTP requests to internal networks, services, or cloud metadata endpoints. The vulnerability exists because the synchronizer's remote stream fetch functionality does not validate destination IP addresses or enforce restrictions against private, loopback, or link-local network ranges despite checking the URL scheme.

Detection Guidance

To detect this vulnerability, check if your OpenCTI instance is running a version prior to 7.260701.0. Review logs for suspicious outbound HTTP requests from OpenCTI to internal or cloud metadata endpoints. Monitor for unusual connection errors or responses that could indicate internal network scanning.

Impact Analysis

An attacker could scan and fingerprint internal services like Elasticsearch, Redis, or databases. They could access internal-only HTTP services or retrieve responses from internal endpoints if they match stream collection formats. Connection errors could also reveal information about open HTTP ports, non-HTTP ports, or closed ports, enabling internal network scanning.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized access to internal services and data. The SSRF flaw allows attackers to scan internal networks, access internal-only services, or retrieve responses from internal endpoints, which may expose sensitive data. GDPR requires protecting personal data, while HIPAA mandates securing protected health information. Unauthorized network scanning and data exposure risks could lead to non-compliance with these regulations.

Mitigation Strategies

Upgrade OpenCTI to version 7.260701.0 or later immediately. Configure the URI deny list in production.json or via environment variables to block internal, private, loopback, and link-local addresses. Restrict ingestion privileges to trusted accounts only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76820. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart