CVE-2026-57953
Last modified
CVE-2026-57953 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Its-A-Feature | Mythic | < 3.4.0.60 |
References
- https://github.com/its-a-feature/Mythic/issues/565Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57953?
How severe is CVE-2026-57953?
How do I fix CVE-2026-57953?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57948Pinpoint through version 3.1.0 contains an insecure session …7.6
- CVE-2026-57949ruoyi-vue-pro through 2026.05, fixed in commit c779a47, cont…7.1
- CVE-2026-5795In Eclipse Jetty, the class JASPIAuthenticator initiates the…7.4
- CVE-2026-57950ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 conta…8.6
- CVE-2026-57951Mythic before 3.4.0.60 contains a broken hasura permission f…7.1
- CVE-2026-57952Mythic before 3.4.0.60 contains an authorization bypass vuln…6.5
- CVE-2026-57954Elide through 7.1.17 fails to enforce @ReadPermission on cli…5.3
- CVE-2026-57955SigNoz through 0.130.1 contains a SQL injection vulnerabilit…8.5
- CVE-2026-57956SigNoz before 0.133.0 contains a broken access control vulne…6.4
- CVE-2026-57957Papermark through 0.22.0 contains a cross-origin resource sh…4.7
- CVE-2026-57958Mixpost through 2.6.0 contains a reflected cross-site script…6.1
- CVE-2026-57959Hi.Events through 1.9.0 contains a promo code validation vul…8.2
Are you affected by CVE-2026-57953?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
