# Vulnerability Accept Risk

POST /easm/vulnerabilities/search:accept-risk: Accepts the risk of the asset vulnerabilities that match filters (risk_accepted).

Source: https://docs.deepinfo.com/reference/easm/vulnerability-accept-risk/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/easm/vulnerabilities/search:accept-risk`

Accepts the risk of the asset vulnerabilities that match `filters` (`risk_accepted`).

The action applies to **every record matching `filters`**. Always send a filter (for example by `id`); an empty filter matches all records.

> State changes are applied **asynchronously**: the new state is visible a few seconds after the response. The response body only reports how many records matched.

## Authentication

Send your API key in the `apikey` request header.

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      },
      {
        "name": "cve.id",
        "type": "eq",
        "value": "CVE-0000-0002"
      }
    ]
  }
}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `asset` | The affected asset's name, for filtering: a domain, subdomain or IP address, or for a website asset `host:port`. Filter with `eq` and the exact name to get one asset's CVEs; responses carry it in `asset.name`. |
| `domain_asset` | The name of the domain asset the affected asset belongs to, for filtering (for a domain, its own name); responses carry it in `asset.domain_asset.name`. |
| `asset_tags` | Your own tags on the affected asset, for filtering; responses carry them in `asset.tags`. |
| `technologies.vendor` | Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
| `technologies.product` | Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`. |
| `technologies.version` | Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected. |
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects. |
| `cve.enrichment.vdeep_metric.cvss_version` | CVSS version of the CVE's main CVSS assessment, the one the `cvss_data` fields come from, for example `3.1`, `3.0` or `2.0`. |
| `cve.enrichment.cwe.owasptop10_2021` | OWASP Top 10 (2021) category of a CWE weakness linked to the CVE, for example `A03 Injection` or `A01 Broken Access Control`; empty when the CWE has none. The platform shows it as the OWASP chip. |
| `cve.enrichment.cwe.name` | Name of a CWE weakness linked to the CVE, for example `Out-of-bounds Write` or `Improper Input Validation`. |
| `cve.enrichment.cwe.description` | The CWE catalog's description of a weakness linked to the CVE. |
| `cve.enrichment.cwe.scope` | Security areas a CWE weakness of the CVE can affect, from the CWE entry. Values seen: `Confidentiality`, `Integrity`, `Availability`, `Access Control`, `Authentication`, `Authorization`, `Accountability`, `Non-Repudiation`, `Other`. |
| `cve.enrichment.cwe.impact` | Technical impacts a CWE weakness of the CVE can have, from the CWE entry, for example `Execute Unauthorized Code or Commands`, `Read Memory` or `DoS: Crash, Exit, or Restart`. |
| `cve.enrichment.cwe.detection_method` | Methods that can detect a CWE weakness of the CVE, from the CWE entry, for example `Automated Static Analysis`, `Fuzzing` or `Manual Analysis`; the platform shows them as DETECTION METHOD. |
| `cve.enrichment.cisa_kev.vendor_project` | Vendor or project named in the CVE's CISA Known Exploited Vulnerabilities (KEV) catalog entry, for example `Apache` or `Microsoft`; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.product` | Product named in the CVE's CISA KEV entry, for example `Log4j2` or `Multiple Products`. |
| `cve.enrichment.cisa_kev.vulnerability_name` | Name of the vulnerability in the CVE's CISA KEV entry, for example `Apache Log4j2 Remote Code Execution Vulnerability`. |
| `cve.enrichment.cisa_kev.short_description` | CISA's short description of the vulnerability in the CVE's KEV entry. |
| `cve.enrichment.cisa_kev.required_action` | Action CISA requires in the CVE's KEV entry, for example `Apply updates per vendor instructions.` |
| `cve.enrichment.cisa_kev.known_ransomware_campaign_use` | Whether the CVE's CISA KEV entry reports use in ransomware campaigns: `Known` or `Unknown`; the platform adds a RANSOMWARE badge for `Known`. |
| `cve.enrichment.cisa_kev.notes` | Notes in the CVE's CISA KEV entry, often reference URLs. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.cwe.capec_id` | IDs of CAPEC attack patterns related to a CWE weakness of the CVE, as numbers; the platform shows them as `CAPEC-<id>` under ATTACK STAGES. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.epss_score.percentile` | Percentile of the CVE's EPSS score among all scored CVEs, from 0 to 1 (`0.95` means 95% of them have the same or a lower score). |
| `cve.enrichment.epss_score.date` | Date of the CVE's EPSS score, as a UTC date-time at midnight (for example `2026-09-23T00:00:00Z`); the platform shows it as ANALYSIS DATE. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `cve.enrichment.cisa_kev.due_date` | Remediation due date in the CVE's CISA KEV entry, as a UTC date-time at midnight, shown as REMEDIATION DUE. CVEs that have it get the red EXPLOITABLE pill. |
| `first_seen_date` | When the CVE was first detected on this asset, in ISO 8601 UTC. |
| `last_seen_date` | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
| `last_check_date` | When the asset was last checked for this CVE, in ISO 8601 UTC; it equals `last_seen_date` while the CVE is still found and is later once the CVE is `verified_resolved`. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `asset_type` | The affected asset's type, for filtering: `domain`, `subdomain`, `ip` or `website`; responses carry it in `asset.type`. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality` | Confidentiality impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the C of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity` | Integrity impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the I of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability` | Availability impact of the CVE's main CVSS assessment: `NONE`, `PARTIAL` or `COMPLETE` for CVSS 2.0, `NONE`, `LOW` or `HIGH` for CVSS 3.x. The platform shows it as the A of the C/I/A chip. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `state` | The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `is_certain` | `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
| `is_potential` | `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |

### Sortable Fields

| Field | Description |
|---|---|
| `asset.name` | The affected asset's name: a domain, subdomain or IP address, or for a website asset `host:port`. Sort only; filter with `asset`. |
| `asset.type` | The affected asset's type: `domain`, `subdomain`, `ip` or `website`. Sort only; filter with `asset_type`. |
| `asset.domain_asset.name` | The name of the domain asset the affected asset belongs to (for a domain, its own name); null when the asset's domain is not one of your assets. Sort only; filter with `domain_asset`. |
| `technologies.vendor` | Vendor of a technology detected on the affected asset, as a lower-case identifier such as `apache`, `php` or `jquery`. In the samples every CVE record of the same asset carries the same technology list, so the list describes the asset, not the CVE. |
| `technologies.product` | Product name of a technology detected on the affected asset, as a lower-case identifier such as `http_server`, `php` or `bootstrap`. |
| `technologies.version` | Detected version of that technology on the affected asset, such as `1.0.0`; empty when no version was detected. |
| `cve.id` | The CVE identifier, such as `CVE-2021-44228`; filter on it to list the assets the CVE affects. |
| `cve.published` | When the CVE was first published, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). |
| `cve.last_modified` | When the CVE record was last changed, in ISO 8601 UTC. |
| `cve.enrichment.vdeep_metric.cvss_data.base_score` | CVSS base score of the CVE's main CVSS assessment, from 0 to 10. The platform shows it as SCORE/SEVERITY. |
| `cve.enrichment.vdeep_metric.cvss_data.base_severity` | Severity of the CVE's main CVSS assessment: `critical`, `high`, `medium`, `low`, `none` or `unknown`; CVSS 2.0 has no `critical`, so a 2.0 score of 10 is `high`. The Vulnerability List severity tabs filter on it. |
| `cve.enrichment.cwe.id` | Number of a CWE weakness linked to the CVE, for example `787` for CWE-787; a CVE can have several CWEs or none. The platform shows it as `CWE-<id>` after the CWE name. |
| `cve.enrichment.epss_score.epss` | EPSS score of the CVE: the estimated probability, from 0 to 1, that it will be exploited in the next 30 days. The platform shows it as a percentage. |
| `cve.enrichment.cisa_kev.date_added` | Date the CVE was added to the CISA KEV catalog, as a UTC date-time at midnight, shown as ADDED TO KEV; empty for CVEs not in the catalog. |
| `first_seen_date` | When the CVE was first detected on this asset, in ISO 8601 UTC. |
| `last_seen_date` | When the CVE was most recently detected on this asset, in ISO 8601 UTC. |
| `state` | The CVE's state on this asset: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |
| `is_certain` | `true` when the CVE on this asset has been verified through testing and confirmed as valid (Certain). In the samples each record is either certain or potential, never both. |
| `is_potential` | `true` when the CVE on this asset has been identified through testing but not yet confirmed (Potential). |

## Response Fields

| Field | Type |
|---|---|
| `asset_vulnerability_count` | integer |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `asset_vulnerability_count` | number |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "acme.example"
      },
      {
        "name": "cve.id",
        "type": "eq",
        "value": "CVE-0000-0002"
      }
    ]
  }
}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "asset_vulnerability_count": 1
}
```

### 400 · Malformed JSON

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{"filters": '
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "details": [
    "Invalid JSON data."
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/vulnerabilities/search:accept-risk' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "domain_asset",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset_tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.vendor",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "technologies.version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_version",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.owasptop10_2021",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.scope",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.impact",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cwe.detection_method",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vendor_project",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.vulnerability_name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.short_description",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.required_action",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.known_ransomware_campaign_use",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.cisa_kev.notes",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.published",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.last_modified",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_score",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.cwe.capec_id",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.epss",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.percentile",
        "type": "eq",
        "value": 0
      },
      {
        "name": "cve.enrichment.epss_score.date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.date_added",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "cve.enrichment.cisa_kev.due_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "first_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_check_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "asset_type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_confidentiality",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_integrity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.vulnerable_system_availability",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve.enrichment.vdeep_metric.cvss_data.base_severity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "is_certain",
        "type": "eq",
        "value": true
      },
      {
        "name": "is_potential",
        "type": "eq",
        "value": true
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}'
```
