PT-2026-60250 · Specterops+1 · Bloodhound
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BloodHound versions prior to 9.4.1
Description
An authorization flaw exists in the custom-nodes API endpoints. Authenticated users with valid session tokens can modify the global graph schema by performing unprotected POST, PUT, and DELETE operations on the custom-nodes endpoints. This allows the creation, update, or deletion of custom node types, which impacts all users and tenants.
Recommendations
Update BloodHound to the version containing commit 8f79035.
Restrict access to the custom-nodes API endpoints to authorized administrators only.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bloodhound