PT-2026-53670 · Mythic · Mythic

·

CVE-2026-57952

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mythic versions prior to 3.4.0.60
Description An authorization bypass exists in four REST endpoints: 'c2profile config check webhook', 'c2profile redirect rules webhook', 'c2profile get ioc webhook', and 'c2profile sample message webhook'. These endpoints fail to verify the ownership of the payload. Consequently, an operator within one operation can use a known payload UUID from a different operation to access that operation's C2 profile configuration, which includes callback parameters and encryption keys.
Recommendations Update to version 3.4.0.60 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57952

Affected Products

Mythic