CVE-2026-57951 Details
Description
Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators and spectators can query payload_build_step to read step_stdout, step_stderr, step_name, and step_description across all operations on the server.
A vulnerability exists in Mythic versions prior to 3.4.0.60, where a misconfigured Hasura permission filter on the payload_build_step table allows authenticated operators and spectators to bypass operation-scoped access controls. The filter's '_or' condition is always satisfied, enabling users to query and read step-related logs across all operations on the server, rather than being restricted to their own.
Users can update to Mythic version 3.4.0.60 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| its-a-feature mythic | < 3.4.0.60 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | New CVE Received | [email protected] |