PT-2026-60250 · Specterops+1 · Bloodhound

·

CVE-2026-59255

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions BloodHound versions prior to 9.4.1
Description An authorization flaw exists in the custom-nodes API endpoints. Authenticated users with valid session tokens can modify the global graph schema by performing unprotected POST, PUT, and DELETE operations on the custom-nodes endpoints. This allows the creation, update, or deletion of custom node types, which impacts all users and tenants.
Recommendations Update BloodHound to the version containing commit 8f79035. Restrict access to the custom-nodes API endpoints to authorized administrators only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59255

Affected Products

Bloodhound