VYPR

BloodHound

by SpecterOps

CVEs (2)

  • CVE-2026-59255HigJul 15, 2026
    risk 0.46cvss 7.1epss 0.00

    BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node…

  • CVE-2026-85241MedSep 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to…