Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component. | |
| Title | SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization | |
| First Time appeared |
Specterops
Specterops bloodhound |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:specterops:bloodhound:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Specterops
Specterops bloodhound |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-03T22:30:14.587Z
Reserved: 2026-09-03T15:45:24.645Z
Link: CVE-2026-85241
No data.
Status : Received
Published: 2026-09-03T23:17:20.807
Modified: 2026-09-03T23:17:20.807
Link: CVE-2026-85241
No data.
OpenCVE Enrichment
Updated: 2026-09-03T23:45:04Z