Improper authorization control for web services In pycti

Description

OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd

Summary

An organization admin can escalate their privileges by adding a user from a different organization with higher privileges, to their own organization.

Impact

Full platform access, access to sensitive or proprietary information.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions