CVE-2026-66724 Details
Description
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0
A missing authorization vulnerability has been identified in MWDB Core versions 2.0.0 prior to 2.19.0. The issue resides in the deprecated config and blob upload endpoints, which accept an undocumented POST method. This POST method bypasses the capability checks that are enforced on the documented PUT method. As a result, any authenticated user lacking the 'adding_configs' or 'adding_blobs' capabilities can upload config and text blob objects to the system. The vulnerability is limited to the addition of new config and blob objects.
Users can upgrade to MWDB Core version 2.19.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/07/CVE-2026-66723 | [email protected] | BundleRemedy |
| https://github.com/CERT-Polska/mwdb-core/releases/tag/v2.19.0 | [email protected] | Release NotesVendor |
| https://github.com/CERT-Polska/mwdb-core/security/advisories/GHSA-8fv8-wffg-4323 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CERT.PL MWDB Core | >= 2.0.0, < 2.19.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |
Volerion