MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0 | |
| Title | Permission Bypass Via Undocumented HTTP Methods In MWDB Core | |
| First Time appeared |
Cert.pl
Cert.pl mwdb Core |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cert.pl:mwdb_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cert.pl
Cert.pl mwdb Core |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-29T15:04:34.830Z
Reserved: 2026-07-27T15:50:32.128Z
Link: CVE-2026-66724
Updated: 2026-07-29T15:04:23.729Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses