CVE-2026-66724
Last modified
CVE-2026-66724 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CERT.PL | MWDB Core | >= 2.0.0, < 2.19.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66724?
How severe is CVE-2026-66724?
How do I fix CVE-2026-66724?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66711Subscriber Cross Site Scripting (XSS) in WooCommerce Multili…7.1
- CVE-2026-66712Unauthenticated Broken Access Control in Simple Membership <…7.5
- CVE-2026-66713Deserialization of Untrusted Data (CWE-502) in the Tribes-ba…9.8
- CVE-2026-6672The Affiliate Program Suite — SliceWP Affiliates plugin for …6.4
- CVE-2026-66720The GOOSE subscriber component improperly validates the UTC …7.1
- CVE-2026-66723MWDB Core versions >=2.2.0 and <2.19.0 contain a missing aut…7
- CVE-2026-66729facil.io 0.6.0 through 0.7.6 contains an integer underflow v…8.7
- CVE-2026-6673Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5…6.4
- CVE-2026-66730facil.io 0.6.0 through 0.7.6 contains a denial-of-service vu…8.7
- CVE-2026-66731facil.io 0.7.5 through 0.7.6 contains a denial-of-service vu…8.7
- CVE-2026-66732Sonic 3 A.I.R. before commit 2492d18 contains a missing sour…8.3
- CVE-2026-66733Sonic 3 A.I.R. before commit 2492d18 contains an unbounded m…8.7
Are you affected by CVE-2026-66724?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
