CVE-2026-85241
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.27%
- CWE
- CWE-285, CWE-266
- Published
- 2026-09-03
- Last modified
- 2026-09-04
Affected products
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
- SpecterOps BloodHound
Weakness type
Related vulnerabilities
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-58611 — Xbox Gaming Services Elevation of Privilege Vulnerability
- CVE-2026-86277 — SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php authorization
- CVE-2026-86263 — sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization
- CVE-2026-86262 — sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization
- CVE-2026-86261 — sfturing hosp_order Order Controller OrderController.java authorization
- CVE-2026-86283 — MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data
- CVE-2026-86212 — Open5GS AMF/MME improper authorization