SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66723

HIGH · CVSS 7 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

MWDB Core versions from 2.2.0 to 2.19.0 are vulnerable due to a missing authorization check in the Remote Instances proxy API, allowing unauthenticated attackers to exploit the API key's permissions. This could lead to unauthorized actions on the remote MWDB instance, potentially compromising sensitive data or functionality. Organizations using affected versions with Remote Instances configured should prioritize upgrading to version 2.19.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66723
Severity
HIGH
CVSS
7
EPSS
0.49%

Original NVD Description

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance using the identity and permissions associated with the configured API key. This can result in unauthorized actions being performed on the remote instance as if executed by the user whose API key was used to set up the remote instance. The vulnerability is limited to deployments where Remote Instances have been configured.This issue has been fixed in versionĀ 2.19.0