CVE-2026-66724

Source
https://cve.org/CVERecord?id=CVE-2026-66724
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66724.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66724
Aliases
  • GHSA-8fv8-wffg-4323
Published
2026-07-29T14:12:25Z
Modified
2026-08-12T03:51:09Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Permission Bypass Via Undocumented HTTP Methods In MWDB Core
Details

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0

Database specific
{
    "cna_assigner": "CERT-PL",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66724.json"
}
References

Affected packages

Git / github.com/cert-polska/mwdb-core

Affected ranges

Type
GIT
Repo
https://github.com/cert-polska/mwdb-core
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.19.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.0.0
v2.1.0
v2.1.1
v2.1.2
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.11.0
v2.12.0
v2.13.0
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.17.0
v2.18.0
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.3.0-rc1
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66724.json"