← Back to CVE List
CVE-2026-63477NVD
Vulnerability Summary
Summary An Organization Administrator (a non-global-admin user holding the virtual `VIRTUAL_ORGANIZATION_ADMIN` capability plus the common `KNOWLEDGE_KNUPDATE` capability) can promote themselves to full global administrator. The fix for CVE-2026-44730 added a check in `userAddRelation`/`addUser` that only lets an org admin add a user to a group present in `administrated_organizations[].grantable_groups`. However, an org admin can freely set their own organization's `grantable_groups` to any group — including the built-in Administrators group — through `organizationFieldPatch`, which performs no validation of the supplied group ids. After widening their own grant scope, the org admin passes the new guard and adds themselves to the Administrators group, which carries the `BYPASS` capability (global admin). Details The (correct) guard added for CVE-2026-44730 — `opencti-platform/opencti-graphql/src/domain/user.js`: `userAddRelation` (≈ line 1231): ```js // Check in case organization admins adds non-grantable group a user const myGrantableGroups = R.uniq(user.administrated_organizations.map((orga) => orga.grantable_groups).flat()); if (isOnlyOrgaAdmin(user)) { if (input.relationship_type === 'member-of' && !myGrantableGroups.includes(input.toId)) { throw ForbiddenAccess(); } } ``` `addUser` has the mirror guard (≈ line 748): ```js const myGroupIds = R.uniq(user.administrated_organizations.map((orga) => orga.grantable_groups).flat()); if (!newUser.groups.every((group) => myGroupIds.includes(group))) { throw ForbiddenAccess(); } ``` Both gate group assignment solely against `grantable_groups` of the administrated organizations. The unvalidated write — `grantable_groups` is an editable attribute of an Organization (`opencti-platform/opencti-graphql/src/modules/organization/organization.ts`, attribute `grantable_groups`, and `opencti-platform/opencti-graphql/src/domain/attribute-utils.ts` lists it as editable). It is patched via: `modules/organization/organization-resolver.ts` -> `organizationEditField` (`modules/organization/organization-domain.ts:78`) -> `stixDomainObjectEditField` (`domain/stixDomainObject.js:300`). `stixDomainObjectEditField` validates only `x_opencti_score`, markings, and `created_by`. The `grantable_groups` value flows straight into `updateAttribute` with no check that the supplied group ids are within the actor's grant power, no org-scope restriction, and no allowlist of editable keys. The only special handling of `grantable_groups` (line 339) is a session cache-refresh side effect, not a security check. Authorization to reach the patch — `organizationFieldPatch` is gated `@auth(for: [KNOWLEDGE_KNUPDATE, SETTINGS_SETACCESSES])` (`modules/organization/organization.graphql`). `KNOWLEDGE_KNUPDATE` alone is sufficient. Organization entities are listed in `STIX_ORGANIZATIONS_UNRESTRICTED` (`schema/stixDomainObject.ts:190`), so organization segmentation does not block access, and orgs carry no `restricted_members` by default — therefore `validateUserAccessOperation(... EDIT ...)` returns allowed and the org admin can patch the organization they administer. Why `member-of` -> Administrators = global admin — The default `Administrators` group (`database/data-initialization.js:402`) has `has-role` to the `Administrator role`, whose capabilities are `[BYPASS]`. `buildCompleteUsers` (`domain/user.js:1629`) derives a user's capabilities from `member-of -> group -> has-role -> has-capability`. Once the actor is `member-of` Administrators, they hold `BYPASS` (global admin) on their next session reload, which `organizationUsersCacheRefresh` (`modules/organization/organization-domain.ts:60`) triggers for org members on organization edit. The `isOnlyOrgaAdmin` predicate (`utils/access.ts:631`) is `VIRTUAL_ORGANIZATION_ADMIN && !SETTINGS_SET_ACCESSES`; the virtual capability is appended to any user listed in an org's `authorized_authorities` (`domain/user.js:1763`). Impact A tenant-scoped Organization Administrator (intended to manage only users/groups within their own organization's grant boundary) escalates to full global administrator with the `BYPASS` capability. This grants read/write over every organization's data, all users, roles, capabilities, settings, markings (TLP), connectors and ingestion — a complete confidentiality and integrity compromise of the entire platform across all tenants. This reopens the exact privilege boundary that CVE-2026-44730 was intended to close, because the new guard validates the assignment target against `grantable_groups` while `grantable_groups` itself remains attacker-writable.
CVSS v3.1 Base Metrics — Score 8.8
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- opencti < 7.260624.0
- opencti >= 7.260624.0