CVE-2026-63098
MEDIUMTheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
Title source: cnaDescription
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/TheHive.md#finding-1-get-apistatus-exposes-attachment-protection-password-without-authentication
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/thehive-unauthenticated-information-disclosure-via-api-status-endpoint
Scores
CVSS v3
5.3
EPSS
0.0032
EPSS Percentile
24.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (2)
strangebee/thehive
< 4.1.24
TheHive-Project/TheHive
< 4.1.24
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026