Junglewise Threat Intelligence

CVE-2026-63098: TheHive-Project TheHive information disclosure in api/status endpoint

CVE-2026-63098 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Executive brief

TheHive, a popular open-source incident response platform, contains a security flaw that allows anyone with network access to view sensitive system configuration details without logging in. An attacker can use this information to discover internal network addresses, authentication settings, and passwords used to protect file attachments. This exposure could help an attacker plan further strikes against the organization's security operations data.

Technical details

A missing authentication check (CWE-306) in the StatusCtrl.scala handler of TheHive allows unauthenticated GET requests to the /api/status endpoint. This endpoint returns a JSON response containing sensitive configuration parameters, including the datastore attachment protection password, SSO settings, MFA capabilities, and internal clustered node addresses/roles. The vulnerability is reachable over the network without any prior credentials or user interaction. While the product repository was archived in late 2025, this flaw affects all versions up to and including 4.1.24.

Affected products

  • TheHive-Project TheHive <= 4.1.24

Timeline

  • 2026-07-17: advisory: NVD and VulnCheck published the advisory.

References

Related threats