Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-63099

CVE-2026-63099: TheHive Auth Bypass Vulnerability

CVE-2026-63099 is an authentication bypass flaw in TheHive through version 4.1.24 that allows authenticated users to access attachments from other organizations. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-63099 Overview

CVE-2026-63099 is a broken object-level authorization vulnerability in TheHive through version 4.1.24. The flaw resides in the attachment download endpoints, where the AttachmentSrv.visible function operates as a pass-through traversal without enforcing organization-scoped authorization checks. Any authenticated user can supply a content-hash identifier to download attachments belonging to other organizations. The vulnerability is classified under CWE-639: Authorization Bypass Through User-Controlled Key and enables cross-organization data disclosure in multi-tenant TheHive deployments used for security incident response.

Critical Impact

Authenticated attackers can access sensitive incident-response attachments across organizational boundaries, exposing forensic evidence, malware samples, and case data belonging to unrelated tenants.

Affected Products

  • TheHive through 4.1.24
  • TheHive Project incident response platform (multi-organization deployments)
  • Datastore attachment endpoints exposed by AttachmentSrv

Discovery Timeline

  • 2026-07-17 - CVE-2026-63099 published to NVD
  • 2026-07-17 - Last updated in NVD database

Technical Details for CVE-2026-63099

Vulnerability Analysis

TheHive is an open-source Security Incident Response Platform (SIRP) that supports multi-organization tenancy. Analysts across separate organizations store case attachments — forensic artifacts, malware samples, screenshots, and evidence files — inside a shared datastore. The application identifies each attachment by its content hash and exposes download endpoints for authenticated users.

The vulnerability stems from the AttachmentSrv.visible method, which is implemented as a pass-through and does not validate whether the requesting user's organization owns the referenced attachment. An authenticated user in Organization A can request an attachment hash referenced by a case in Organization B and receive the file contents. The endpoint acts as a direct object reference keyed by hash, granting horizontal access across tenant boundaries.

Root Cause

The root cause is a missing organization-scoped authorization check in the attachment retrieval path. The visible predicate returns without evaluating tenant membership against the attachment's owning case. Content-hash identifiers behave as unauthenticated object keys once a session exists, violating the multi-tenant isolation model that TheHive advertises for shared deployments.

Attack Vector

Exploitation requires low-privilege authenticated access to any organization on the target TheHive instance. The attacker enumerates or obtains valid attachment content hashes — through leaked case exports, log entries, guessing, or hash collection from prior legitimate access — and issues authenticated HTTP GET requests to the attachment download endpoint. The server returns attachment contents regardless of the requesting organization. See the VulnCheck Security Advisory and the GitHub TheHive Analysis for the full technical walkthrough of the AttachmentSrv.visible pass-through behavior.

Detection Methods for CVE-2026-63099

Indicators of Compromise

  • Unexpected attachment download requests from user accounts to hashes not associated with cases in their organization.
  • Elevated volume of requests to /api/datastore/ or /api/v1/datastore/ endpoints from a single authenticated session.
  • Attachment access events where the requesting user's organization does not match the parent case's organization in TheHive audit logs.

Detection Strategies

  • Correlate TheHive application logs against the case-to-organization mapping to flag cross-tenant hash access.
  • Deploy web application firewall (WAF) rules that record hash identifiers on datastore endpoints and alert on repeated distinct-hash access patterns.
  • Baseline normal attachment access rates per user and alert on statistical outliers indicative of enumeration.

Monitoring Recommendations

  • Forward TheHive API and audit logs to a centralized SIEM for retention and correlation with authentication events.
  • Enable verbose logging on the datastore controller to capture the requesting user, organization, and content hash for every attachment fetch.
  • Review privileged and analyst account activity for bulk downloads spanning multiple hashes over short windows.

How to Mitigate CVE-2026-63099

Immediate Actions Required

  • Restrict TheHive access to trusted networks and enforce strong authentication for all analyst accounts.
  • Audit existing multi-organization deployments for cross-tenant attachment access using application and datastore logs.
  • Rotate any secrets, credentials, or sensitive evidence that may have been shared as attachments and could have been exposed.

Patch Information

At the time of publication, no fixed version was listed in the NVD entry for TheHive beyond version 4.1.24. Monitor the VulnCheck Security Advisory and the TheHive Project release channels for an official patched build addressing the AttachmentSrv.visible authorization gap.

Workarounds

  • Segment TheHive deployments per organization instead of relying on the multi-tenant model until a patch is applied.
  • Place a reverse proxy in front of TheHive that validates the requesting user's organization against the requested attachment metadata before proxying to /api/datastore/.
  • Limit user accounts to the minimum roles required and remove dormant analyst accounts that increase the authenticated attack surface.
bash
# Example reverse-proxy allowlist restricting datastore endpoints to internal analyst subnet
location /api/datastore/ {
    allow 10.20.0.0/24;
    deny all;
    proxy_pass http://thehive-backend:9000;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.