{"id":"CVE-2026-63099","summary":"TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints","details":"TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization check in AttachmentSrv.visible, which is implemented as a pass-through traversal, to download arbitrary attachments.","modified":"2026-07-19T03:46:09.017430147Z","published":"2026-07-17T15:39:44.235Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63099.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-639"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63099.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63099"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/thehive-broken-object-level-authorization-via-attachment-download-endpoints"},{"type":"PACKAGE","url":"https://github.com/TheHive-Project/TheHive"},{"type":"EVIDENCE","url":"https://github.com/geo-chen/oss/blob/main/TheHive.md#finding-2-cross-organisation-attachment-disclosure-via-unauthorized-datastore-endpoint-missing-object-level-authorization"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thehive-project/thehive","events":[{"introduced":"0"},{"last_affected":"b6649bb58938a414de9f0505cc0a1dad15f0d0ef"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"4.1.24"}]}}],"versions":["4.1.24","4.1.23","4.1.22","4.1.21","4.1.20","4.1.19","4.1.18","4.1.17","4.1.16","4.1.15","4.1.14","4.1.13","4.1.12","4.1.11","4.1.10","4.1.9","4.1.8","4.1.7","4.1.6","4.1.5","4.1.4","4.1.3","4.1.2","4.1.1","4.1.0","4.0.5","4.0.4","4.0.3","4.0.2","4.0.0","4.0.0-RC3","4.0.0-RC2","4.0.0-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63099.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}