CVE-2023-39069: Strangebee Cortex

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.

Affected products

  • Strangebee Cortex: up to and including 3.1.6
  • Strangebee Thehive: before 3.5.2 (fixed in 3.5.2); from 4.0.0, up to and including 4.1.21; from 5.0.0, up to and including 5.0.8

Published 2023-09-11. Last modified 2026-06-17.