CVE-2026-85241 Details
Description
A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.
An improper authorization vulnerability has been identified in SpecterOps BloodHound versions through 9.5.1. The issue resides in the Graph Write Endpoint, specifically within the NewV2API function of the file cmd/api/src/api/registration/v2.go. This vulnerability allows for remote exploitation by manipulating the authorization requirements of certain API endpoints.
Users can upgrade to BloodHound versions 9.6.0-rc1, 9.6.0, or 9.7.0-rc3 to address this vulnerability. After upgrading, the Graph Write API will require the appropriate permissions to modify domain entities, preventing unauthorized changes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SpecterOps/BloodHound/ | [email protected] | Vendor |
| https://github.com/SpecterOps/BloodHound/commit/39d1276a63e95a7713f954dea632a19651d9cebb | [email protected] | Source CodeVendor |
| https://github.com/SpecterOps/BloodHound/releases/tag/v9.6.0-rc1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-85241 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/894488 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398471 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/398471/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SpecterOps BloodHound | <= 9.5.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion