A vulnerability was found in OpenCTI up to 6.9.4. It has been declared as problematic. This affects an unknown function of the file safeEjs.ts. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability was named CVE-2026-39980. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.