PT-2026-65809 · Mwdb Core · Mwdb Core

CVE-2026-66723

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions MWDB Core versions 2.2.0 through 2.18.x
Description A missing authorization issue exists in the Remote Instances proxy API. The proxy API fails to verify authentication for incoming requests, which allows an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance. These requests are executed using the identity and permissions of the API key configured for the remote instance, potentially leading to unauthorized actions. This issue only affects deployments where Remote Instances have been configured.
Recommendations Update MWDB Core to version 2.19.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66723
GHSA-942C-R7QJ-W895

Affected Products

Mwdb Core