CVE-2026-66723 Details
Description
MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance using the identity and permissions associated with the configured API key. This can result in unauthorized actions being performed on the remote instance as if executed by the user whose API key was used to set up the remote instance. The vulnerability is limited to deployments where Remote Instances have been configured.This issue has been fixed in version 2.19.0
A missing authorization vulnerability has been identified in the Remote Instances proxy API of MWDB Core versions 2.2.0 prior to 2.19.0. The vulnerability allows unauthenticated remote attackers to send arbitrary requests to a remote MWDB instance using the identity and permissions of the configured API key. This could result in unauthorized actions being performed on the remote instance as if they were executed by the user associated with the API key. The issue is present only in deployments where Remote Instances have been configured.
The vulnerability has been fixed in MWDB Core version 2.19.0. Users can also disable the Remote API in older versions by removing the relevant configuration sections from the mwdb.ini file.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/07/CVE-2026-66723 | [email protected] | BundleRemedy |
| https://github.com/CERT-Polska/mwdb-core/releases/tag/v2.19.0 | [email protected] | Release NotesVendor |
| https://github.com/CERT-Polska/mwdb-core/security/advisories/GHSA-942c-r7qj-w895 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MWDB Core | >= 2.2.0, < 2.19.0 (semver) >= 2.0.0, < 2.19.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |
Volerion