PT-2026-60792 · Thehive+1 · Thehive
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TheHive versions prior to 4.1.25
Description
An issue exists in the attachment download endpoints where a broken object-level authorization allows any authenticated user to access attachments from other organizations. This occurs because the
AttachmentSrv.visible() function, which operates as a pass-through traversal, lacks an organization-scoped authorization check. An attacker can exploit this by providing a content-hash identifier to download arbitrary attachments.Recommendations
Update to version 4.1.25 or later.
As a temporary mitigation, restrict access to the attachment download endpoints to trusted users only.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thehive