5.3 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): Not Defined (X)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
6 packages
- bloodhound-py
- haskellPackages.bloodhound
- python313Packages.bloodhound
- python314Packages.bloodhound
- python313Packages.bloodhound-py
- python314Packages.bloodhound-py
- @LeSuisse accepted
- @LeSuisse published on GitHub
SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
References
-
VDB-398471 | SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization technical-descriptionvdb-entry
-
-
CVE-2026-85241 | CVE Analysis and Report third-party-advisory
-
Submit #894488 | SpecterOps BloodHound 9.4.0 Improper Authorization third-party-advisory
Affected products
- ==9.5.0
- ==9.6.0-rc1
- ==9.7.0-rc3
- ==9.5.1
- ==9.6.0
- ==9.0.0
- ==9.1.0
- ==9.4.0
- ==9.2.2
Matching in nixpkgs
pkgs.bloodhound
Active Directory reconnaissance and attack path management tool
Ignored packages (6)
pkgs.bloodhound-py
Python based ingestor for BloodHound, based on Impacket
pkgs.haskellPackages.bloodhound
Elasticsearch client library for Haskell
pkgs.python313Packages.bloodhound
Python based ingestor for BloodHound, based on Impacket
-
nixos-unstable -
- nixos-unstable-small 1.9.0
pkgs.python314Packages.bloodhound
Python based ingestor for BloodHound, based on Impacket
-
nixos-unstable -
- nixos-unstable-small 1.9.0
pkgs.python313Packages.bloodhound-py
None
Package maintainers
-
@AkechiShiro Samy Lahfa <akechishiro-aur+nixpkgs@lahfa.xyz>
-
@42LoCo42 Eleonora <leonsch@protonmail.com>