PT-2026-65810 · Mwdb Core · Mwdb Core
CVE-2026-66724
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MWDB Core versions 2.0.0 through 2.18.x
Description
Missing authorization in deprecated config and blob upload endpoints allows authenticated users to bypass capability checks. While the documented PUT method is protected, these endpoints also accept an undocumented POST method that ignores requirements for
adding configs or adding blobs capabilities. This enables users to upload new config and text blob objects to the system.Recommendations
Update MWDB Core to version 2.19.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mwdb Core