CVE-2026-66723

Source
https://cve.org/CVERecord?id=CVE-2026-66723
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66723.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66723
Aliases
  • GHSA-942c-r7qj-w895
Published
2026-07-29T14:12:35.422Z
Modified
2026-07-30T04:02:23.781936094Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Missing authentication requirement in Remote Instances proxy API in MWDB Core
Details

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance using the identity and permissions associated with the configured API key. This can result in unauthorized actions being performed on the remote instance as if executed by the user whose API key was used to set up the remote instance. The vulnerability is limited to deployments where Remote Instances have been configured.This issue has been fixed in versionĀ 2.19.0

Database specific
{
    "cna_assigner": "CERT-PL",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66723.json",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/cert-polska/mwdb-core

Affected ranges

Type
GIT
Repo
https://github.com/cert-polska/mwdb-core
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.2.0"
        },
        {
            "fixed": "2.19.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.11.0
v2.12.0
v2.13.0
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.17.0
v2.18.0
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.3.0-rc1
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66723.json"