CVE-2026-85241
SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
| CWE | CWE-285 CWE-266 |
| Vendor | specterops |
| Product | bloodhound |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for specterops bloodhound
Be the first to know when new medium vulnerabilities affecting specterops bloodhound are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
SpecterOps / BloodHound
9.0.0 9.1.0 9.2.2 9.4.0 9.5.0 9.5.1
References
vuldb.com: https://vuldb.com/vuln/398471 vuldb.com: https://vuldb.com/vuln/398471/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85241 vuldb.com: https://vuldb.com/submit/894488 github.com: https://github.com/SpecterOps/BloodHound/commit/39d1276a63e95a7713f954dea632a19651d9cebb github.com: https://github.com/SpecterOps/BloodHound/releases/tag/v9.6.0-rc1 github.com: https://github.com/SpecterOps/BloodHound/
Credits
๐ b1d0ws (VulDB User) VulDB Vulnerability Moderation Team