Impact
SpecterOps BloodHound is affected by a flaw in the NewV2API function of the Graph Write Endpoint, allowing a remote attacker to manipulate graph data without proper authorization. This omission is an improper authorization weakness that enables an attacker to create, modify, or delete graph entries, potentially compromising the integrity of the stored data and enabling further lateral movement or privilege escalation. The vulnerability is tied to CWE‑266 (Improper Authorization) and CWE‑285 (Improper Authentication), indicating that access controls are not correctly enforced for the endpoint.
Affected Systems
The vulnerability exists in SpecterOps BloodHound versions up to 9.5.1. Versions 9.6.0‑rc1, 9.6.0, and 9.7.0‑rc3 include the fix identified by commit 39d1276a63e95a7713f954dea632a19651d9cebb. Users running the affected software should review their version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the lack of an EPSS score means the exploitation probability is unknown from the public data. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely by sending crafted requests to the Graph Write Endpoint, and because the flaw is an authorization bypass, it can result in significant data tampering or unauthorized access without requiring local privileges.
OpenCVE Enrichment