CVE-2026-66723
Received Received - Intake

Missing Authorization in MWDB Core Remote Instances Proxy API

Vulnerability report for CVE-2026-66723, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: CERT.PL

Description

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance using the identity and permissions associated with the configured API key. This can result in unauthorized actions being performed on the remote instance as if executed by the user whose API key was used to set up the remote instance. The vulnerability is limited to deployments where Remote Instances have been configured.This issue has been fixed in versionΒ 2.19.0

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in MWDB Core versions between 2.2.0 and 2.19.0. The Remote Instances proxy API fails to verify authentication for incoming requests, allowing unauthenticated attackers to send arbitrary requests to a remote MWDB instance using the permissions of the configured API key. This could let attackers perform unauthorized actions as if they were the user whose API key was used.

Detection Guidance

Check MWDB Core versions between 2.2.0 and 2.18.9 for Remote Instances proxy API usage. Inspect network traffic for unauthenticated requests to the proxy API endpoint. Review logs for unauthorized actions performed by the configured API key.

Impact Analysis

If you use MWDB Core with Remote Instances configured, an attacker could exploit this to perform actions on your remote instance without authentication. This might include accessing sensitive data, modifying configurations, or disrupting services, depending on the permissions of the API key used.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized actions could result in data exposure, loss of integrity, or failure to meet security controls mandated by these standards.

Mitigation Strategies

Upgrade MWDB Core to version 2.19.0 or later. Disable Remote Instances configuration if not required. Rotate API keys used for Remote Instances configuration. Monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66723. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart