TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strangebee
Strangebee thehive |
|
| CPEs | cpe:2.3:a:strangebee:thehive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Strangebee
Strangebee thehive |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thehive-project
Thehive-project thehive |
|
| Vendors & Products |
Thehive-project
Thehive-project thehive |
Fri, 17 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials. | |
| Title | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-17T15:38:08.061Z
Updated: 2026-07-28T01:50:01.477Z
Reserved: 2026-07-15T15:45:44.601Z
Link: CVE-2026-63098
Updated: 2026-07-17T17:26:49.767Z
Status : Analyzed
Published: 2026-07-17T16:17:16.947
Modified: 2026-07-30T14:25:41.573
Link: CVE-2026-63098
No data.