BRIEFING NOTE: CVE-2026-39980 OVERVIEW CVE-2026-39980 is a template injection vulnerability in OpenCTI, an open-source cyber threat intelligence management platform. Versions prior to 6.9.5 contain improper sanitization in the safeEjs.ts file, allowing users with Manage customization privileges to execute arbitrary JavaScript code within the OpenCTI platform process during notifier template execution. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.2 (HIGH) with network-based attack vector and low attack complexity. While exploitation requires high-level privileges (Manage customization capability), successful attacks would result in complete compromise of confidentiality, integrity, and availability within the OpenCTI platform process. This represents significant risk to organizations managing sensitive threat intelligence data. EXPLOITATION STATUS There is no evidence of active exploitation at this time. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal, reflected in the low EPSS score of 0.00119. However, organizations running OpenCTI versions before 6.9.5 should prioritize patching to mitigate the risk posed by potentially malicious privileged users or compromised administrative accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9.5CPE matchmatch criteria | cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.