VYPR

BloodHound

by SpecterOps

CVEs (1)

  • CVE-2026-59255Jul 15, 2026
    risk 0.00cvss epss 0.00

    BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node…