PT-2026-65809 · Mwdb Core · Mwdb Core
CVE-2026-66723
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
MWDB Core versions 2.2.0 through 2.18.x
Description
A missing authorization issue exists in the Remote Instances proxy API. The proxy API fails to verify authentication for incoming requests, which allows an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance. These requests are executed using the identity and permissions of the API key configured for the remote instance, potentially leading to unauthorized actions. This issue only affects deployments where Remote Instances have been configured.
Recommendations
Update MWDB Core to version 2.19.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mwdb Core