MWDB Core patches two missing-authorization flaws
CERT Polska found two missing-authorization vulnerabilities in MWDB Core letting attackers bypass API auth and capability checks, fixed in version 2.19.0.
CERT Polska disclosed two vulnerabilities in MWDB Core, a malware repository platform, discovered during its own research and coordinated through its CVD process. CVE-2026-66723 affects the Remote Instances proxy API in versions 2.2.0 through 2.18.x, where incoming requests are not authenticated, allowing an unauthenticated remote attacker to relay arbitrary requests using the identity and permissions of the configured API key. This impacts only deployments that have Remote Instances configured, but can result in unauthorized actions performed on a remote instance under another user's credentials.
CVE-2026-66724 affects deprecated config and blob upload endpoints in versions 2.0.0 through 2.18.x. These endpoints accept an undocumented POST method that bypasses capability checks enforced on the documented PUT method, allowing any authenticated user lacking adding_configs or adding_blobs capabilities to upload config and text blob objects. The impact is limited to unauthorized object creation rather than broader compromise. Both issues are fixed in MWDB Core 2.19.0, and no evidence of active exploitation is mentioned; this is a responsible disclosure advisory rather than a report of in-the-wild attacks.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-66723
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free