SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85241

MEDIUM · CVSS 6.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Graph Write Endpoint of SpecterOps BloodHound versions up to 9.5.1 allows for improper authorization through remote manipulation of the NewV2API function. This could potentially enable unauthorized access to sensitive data or functionalities. Organizations using affected versions should prioritize upgrading to at least version 9.6.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85241
Severity
MEDIUM
CVSS
6.3
EPSS
0.27%

Original NVD Description

A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.