Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0 | |
| Title | Permission Bypass Via Undocumented HTTP Methods In MWDB Core | |
| First Time appeared |
Cert.pl
Cert.pl mwdb Core |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cert.pl:mwdb_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cert.pl
Cert.pl mwdb Core |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-29T15:04:34.830Z
Reserved: 2026-07-27T15:50:32.128Z
Link: CVE-2026-66724
Updated: 2026-07-29T15:04:23.729Z
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization