Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profileconfigcheckwebhook, c2profileredirectruleswebhook, c2profilegetiocwebhook, c2profilesamplemessagewebhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57952.json",
"cwe_ids": [
"CWE-862"
],
"cna_assigner": "VulnCheck"
}{
"cpe": "cpe:2.3:a:its-a-feature:mythic:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.4.0.60"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}