External risk intelligence

OpenCTI Unauthorized Workspace Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-61781

OpenCTI is a platform designed to be a centralized web-based interface for security teams. By nature, it functions as an API-driven web application often deployed in environments where it is accessible to authorized users over the network, making it a likely target for web-based interface exposure.

Citeum Opencti

before 6.8.1

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the OpenCTI platform, a tool for managing cyber threat intelligence, could allow an unauthorized user to delete entire workspaces, including dashboards and investigation cases. This issue affects versions prior to 6.8.1 and stems from a lack of proper authorization checks when deleting workspace-related objects.

  • Unauthorized deletion of user workspaces.
  • Critical for maintaining data integrity.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a request to the GraphQL API that targets a workspace belonging to another user. Without proper validation, the system will allow the deletion of the targeted workspace's objects, leading to the loss of critical threat intelligence data.

  • An attacker needs network access to the API.
  • The attacker must know another user's workspace UUID.
  • Risk includes unauthorized data deletion.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could exploit this vulnerability by deleting entire workspaces, including dashboards and investigation cases, which are critical components of threat intelligence management. This occurs when the GraphQL mutation fails to perform adequate authorization checks, allowing unauthorized users to delete resources they do not own.

  • Workspace data and investigation cases.
  • Unauthorized deletion via API call.
  • Loss of critical threat intelligence.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OpenCTI platform, used for managing cyber threat intelligence, is vulnerable to unauthorized deletion of workspace data via its GraphQL API. This critical vulnerability could allow any unauthenticated attacker to delete dashboards and investigation cases by exploiting a lack of ownership checks. Immediate action is required to identify affected instances, assess their business criticality and network exposure, and determine the accountable owner for remediation.

  • Platform owners should manage the issue.
  • Verify all OpenCTI instances for exposure.
  • Plan and execute the upgrade to version 6.8.1.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenCTI?

OpenCTI is an open-source platform that security teams use to centralize, structure, and analyze cyber threat intelligence. It provides a web-based interface and API for managing complex data sets like investigation cases, dashboards, and various indicators of compromise, serving as a unified knowledge base for tracking digital threats.

How does CVE-2025-61781 work?

This vulnerability is an improper authorization flaw. Because the platform fails to verify if a user actually owns a resource before executing a deletion command, it falls under weakness classes related to incorrect access control. Essentially, the system trusts the request to delete a workspace without checking if the person making that request has permission to touch that specific data.

Do I need to be logged in to trigger this?

The vulnerability involves the WorkspacePopoverDeletionMutation in the GraphQL API. The flaw is not triggered by simply browsing the application; it requires specifically crafting a request that provides the unique identifier (UUID) of a workspace you do not own. If the system does not validate ownership, the command proceeds regardless of the requester's legitimate access rights.

Is my OpenCTI instance at risk?

According to Halo Surface Signal, OpenCTI is typically deployed as an API-driven web application intended for network access. If your instance is exposed to the network where unauthorized parties can interact with its API, the risk is higher. You should evaluate whether your deployment is reachable by untrusted users, as this increases the likelihood of an external actor attempting to target workspace resources.

How do I secure my environment?

The primary response is to update your OpenCTI installation to version 6.8.1 or later. This version includes the necessary authorization checks that prevent the unauthorized deletion of workspaces. Start by auditing your current versions, identifying any instances running code older than 6.8.1, and prioritizing the upgrade to ensure data integrity for your intelligence collections.

References