Junglewise Threat Intelligence

CVE-2026-59255: SpecterOps BloodHound missing authorization in custom-nodes API

CVE-2026-59255 · Severity: high · CVSS 7.1 · Published 2026-07-15

Executive brief

BloodHound, a tool used for analyzing and visualizing complex relationships in security environments, contains a flaw in how it manages custom data types. This vulnerability allows any user with a valid login—even those with restricted, read-only access—to modify the global database structure. An attacker could use this to disrupt operations, corrupt data, or interfere with the visibility of security risks across all users and organizations on the platform.

Technical details

A missing authorization vulnerability (CWE-862) exists in the custom-nodes API endpoints of BloodHound through version 9.4.0. The affected endpoints (POST, PUT, and DELETE on /api/v2/custom-nodes) only required basic authentication (RequireAuth) instead of specific administrative permissions (opengraph:Write). This allows any authenticated user, including those with read-only privileges, to create, update, or delete custom node types. Because these node types are part of the global graph schema, such actions impact all users and tenants. The issue was addressed in commit 8f79035 by enforcing proper permission checks.

Affected products

  • SpecterOps BloodHound through 9.4.0

Timeline

  • 2026-06-20: disclosed: Issue reported on GitHub
  • 2026-07-13: patched: Fix merged into main branch via PR #2989
  • 2026-07-15: advisory: CVE published and NVD entry created

References