CVE Watchtower

← Back to CVE List

CVE-2026-63477NVD

Vulnerability Summary

Summary An Organization Administrator (a non-global-admin user holding the virtual `VIRTUAL_ORGANIZATION_ADMIN` capability plus the common `KNOWLEDGE_KNUPDATE` capability) can promote themselves to full global administrator. The fix for CVE-2026-44730 added a check in `userAddRelation`/`addUser` that only lets an org admin add a user to a group present in `administrated_organizations[].grantable_groups`. However, an org admin can freely set their own organization's `grantable_groups` to any group — including the built-in Administrators group — through `organizationFieldPatch`, which performs no validation of the supplied group ids. After widening their own grant scope, the org admin passes the new guard and adds themselves to the Administrators group, which carries the `BYPASS` capability (global admin). Details The (correct) guard added for CVE-2026-44730 — `opencti-platform/opencti-graphql/src/domain/user.js`: `userAddRelation` (≈ line 1231): ```js // Check in case organization admins adds non-grantable group a user const myGrantableGroups = R.uniq(user.administrated_organizations.map((orga) => orga.grantable_groups).flat()); if (isOnlyOrgaAdmin(user)) { if (input.relationship_type === 'member-of' && !myGrantableGroups.includes(input.toId)) { throw ForbiddenAccess(); } } ``` `addUser` has the mirror guard (≈ line 748): ```js const myGroupIds = R.uniq(user.administrated_organizations.map((orga) => orga.grantable_groups).flat()); if (!newUser.groups.every((group) => myGroupIds.includes(group))) { throw ForbiddenAccess(); } ``` Both gate group assignment solely against `grantable_groups` of the administrated organizations. The unvalidated write — `grantable_groups` is an editable attribute of an Organization (`opencti-platform/opencti-graphql/src/modules/organization/organization.ts`, attribute `grantable_groups`, and `opencti-platform/opencti-graphql/src/domain/attribute-utils.ts` lists it as editable). It is patched via: `modules/organization/organization-resolver.ts` -> `organizationEditField` (`modules/organization/organization-domain.ts:78`) -> `stixDomainObjectEditField` (`domain/stixDomainObject.js:300`). `stixDomainObjectEditField` validates only `x_opencti_score`, markings, and `created_by`. The `grantable_groups` value flows straight into `updateAttribute` with no check that the supplied group ids are within the actor's grant power, no org-scope restriction, and no allowlist of editable keys. The only special handling of `grantable_groups` (line 339) is a session cache-refresh side effect, not a security check. Authorization to reach the patch — `organizationFieldPatch` is gated `@auth(for: [KNOWLEDGE_KNUPDATE, SETTINGS_SETACCESSES])` (`modules/organization/organization.graphql`). `KNOWLEDGE_KNUPDATE` alone is sufficient. Organization entities are listed in `STIX_ORGANIZATIONS_UNRESTRICTED` (`schema/stixDomainObject.ts:190`), so organization segmentation does not block access, and orgs carry no `restricted_members` by default — therefore `validateUserAccessOperation(... EDIT ...)` returns allowed and the org admin can patch the organization they administer. Why `member-of` -> Administrators = global admin — The default `Administrators` group (`database/data-initialization.js:402`) has `has-role` to the `Administrator role`, whose capabilities are `[BYPASS]`. `buildCompleteUsers` (`domain/user.js:1629`) derives a user's capabilities from `member-of -> group -> has-role -> has-capability`. Once the actor is `member-of` Administrators, they hold `BYPASS` (global admin) on their next session reload, which `organizationUsersCacheRefresh` (`modules/organization/organization-domain.ts:60`) triggers for org members on organization edit. The `isOnlyOrgaAdmin` predicate (`utils/access.ts:631`) is `VIRTUAL_ORGANIZATION_ADMIN && !SETTINGS_SET_ACCESSES`; the virtual capability is appended to any user listed in an org's `authorized_authorities` (`domain/user.js:1763`). Impact A tenant-scoped Organization Administrator (intended to manage only users/groups within their own organization's grant boundary) escalates to full global administrator with the `BYPASS` capability. This grants read/write over every organization's data, all users, roles, capabilities, settings, markings (TLP), connectors and ingestion — a complete confidentiality and integrity compromise of the entire platform across all tenants. This reopens the exact privilege boundary that CVE-2026-44730 was intended to close, because the new guard validates the assignment target against `grantable_groups` while `grantable_groups` itself remains attacker-writable.
Severity Level
HIGH(8.8)
Published Date
Oct 2, 2026
Last Modified
Oct 2, 2026
Exploitation Status
No confirmed exploitation yet
CVE Record Status
Reserved
This CVE ID is referenced in a public advisory, but the CVE Program has not published its official CVE Record yet. Full CVSS/CPE data from NVD will appear here once it does.
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 8.8
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • opencti < 7.260624.0
Patched Versions
  • opencti >= 7.260624.0
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.