CVE-2026-66724

Source
https://cve.org/CVERecord?id=CVE-2026-66724
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66724.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66724
Aliases
  • GHSA-8fv8-wffg-4323
Published
2026-07-29T14:12:25.620Z
Modified
2026-07-30T04:02:49.425254073Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Permission Bypass Via Undocumented HTTP Methods In MWDB Core
Details

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the addingconfigs or addingblobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66724.json",
    "cna_assigner": "CERT-PL",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/cert-polska/mwdb-core

Affected ranges

Type
GIT
Repo
https://github.com/cert-polska/mwdb-core
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.19.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.0.0
v2.1.0
v2.1.1
v2.1.2
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.11.0
v2.12.0
v2.13.0
v2.14.0
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.17.0
v2.18.0
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.3.0-rc1
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66724.json"