# MWDB Core patches two missing-authorization flaws

Published: 2026-07-29 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/d9fa7c98-f2cf-558a-bdb8-80b2c130fcea/mwdb-core-patches-two-missing-authorization-flaws

> CERT Polska found two missing-authorization vulnerabilities in MWDB Core letting attackers bypass API auth and capability checks, fixed in version 2.19.0.

CERT Polska disclosed two vulnerabilities in MWDB Core, a malware repository platform, discovered during its own research and coordinated through its CVD process. CVE-2026-66723 affects the Remote Instances proxy API in versions 2.2.0 through 2.18.x, where incoming requests are not authenticated, allowing an unauthenticated remote attacker to relay arbitrary requests using the identity and permissions of the configured API key. This impacts only deployments that have Remote Instances configured, but can result in unauthorized actions performed on a remote instance under another user's credentials.

CVE-2026-66724 affects deprecated config and blob upload endpoints in versions 2.0.0 through 2.18.x. These endpoints accept an undocumented POST method that bypasses capability checks enforced on the documented PUT method, allowing any authenticated user lacking adding_configs or adding_blobs capabilities to upload config and text blob objects. The impact is limited to unauthorized object creation rather than broader compromise. Both issues are fixed in MWDB Core 2.19.0, and no evidence of active exploitation is mentioned; this is a responsible disclosure advisory rather than a report of in-the-wild attacks.

## Mentioned in this report

- Vulnerabilities: CVE-2026-66723, CVE-2026-66724

Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-66723

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d9fa7c98-f2cf-558a-bdb8-80b2c130fcea/mwdb-core-patches-two-missing-authorization-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
