CVE-2026-63099

Source
https://cve.org/CVERecord?id=CVE-2026-63099
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63099.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63099
Published
2026-07-17T15:39:44.235Z
Modified
2026-07-19T03:46:09.017430147Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
Details

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization check in AttachmentSrv.visible, which is implemented as a pass-through traversal, to download arbitrary attachments.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63099.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/thehive-project/thehive

Affected ranges

Type
GIT
Repo
https://github.com/thehive-project/thehive
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.1.24"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

4.*
4.0.0
4.0.0-RC1
4.0.0-RC2
4.0.0-RC3
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.10
4.1.11
4.1.12
4.1.13
4.1.14
4.1.15
4.1.16
4.1.17
4.1.18
4.1.19
4.1.2
4.1.20
4.1.21
4.1.22
4.1.23
4.1.24
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63099.json"