Description
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node types affecting all users and tenants by invoking unprotected POST, PUT, and DELETE operations on the custom-nodes endpoints.
Published: 2026-07-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

BloodHound versions up to 9.4.0 contain a missing authorization check in the custom‑nodes API endpoints. Any user authenticated with a valid session token can use unprotected POST, PUT, and DELETE operations on these endpoints to create, update, or delete custom node types, thereby altering the global graph schema used by all users and tenants. This change can compromise the integrity of modeling data and the overall network representation.

Affected Systems

SpecterOps BloodHound, versions through 9.4.0. The vulnerability was fixed in commit 8f79035, which added authorization checks to the custom‑nodes API.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high risk, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA KEV. The likely attack vector requires a valid authenticated session token; attackers can exploit this vector by sending POST, PUT, or DELETE requests to the custom‑nodes endpoints, resulting in unauthorized changes to the global graph schema.

Generated by OpenCVE AI on July 31, 2026 at 03:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SpecterOps BloodHound to a version that includes commit 8f79035 (e.g., 9.4.1 or later).
  • If a patch upgrade is not immediately available, restrict access to the custom‑nodes API to privileged users only or disable it for non‑admin roles.
  • After remediation, review existing custom node types and remove any that were added by untrusted users to restore the original graph schema.

Generated by OpenCVE AI on July 31, 2026 at 03:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Bloodhound Project
Bloodhound Project bloodhound
CPEs cpe:2.3:a:bloodhound_project:bloodhound:*:*:*:*:*:*:*:*
Vendors & Products Bloodhound Project
Bloodhound Project bloodhound

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Specterops
Specterops bloodhound
Vendors & Products Specterops
Specterops bloodhound

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node types affecting all users and tenants by invoking unprotected POST, PUT, and DELETE operations on the custom-nodes endpoints.
Title BloodHound Missing Authorization on Custom Node Management API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Bloodhound Project Bloodhound
Specterops Bloodhound
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:49:48.861Z

Reserved: 2026-07-04T12:17:14.301Z

Link: CVE-2026-59255

cve-icon Vulnrichment

Updated: 2026-07-15T18:03:40.439Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses