PT-2026-65810 · Mwdb Core · Mwdb Core

CVE-2026-66724

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MWDB Core versions 2.0.0 through 2.18.x
Description Missing authorization in deprecated config and blob upload endpoints allows authenticated users to bypass capability checks. While the documented PUT method is protected, these endpoints also accept an undocumented POST method that ignores requirements for adding configs or adding blobs capabilities. This enables users to upload new config and text blob objects to the system.
Recommendations Update MWDB Core to version 2.19.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66724
GHSA-8FV8-WFFG-4323

Affected Products

Mwdb Core