What is CVE-2026-66723?
CVE-2026-66723 is a missing authorization vulnerability in the Remote Instances proxy API of MWDB Core versions 2.2.0 to 2.19.0. The flaw allows an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance through a vulnerable instance without authentication. Affected systems should be immediately updated to version 2.19.0 or later.
Azərbaycanca: CVE-2026-66723, MWDB Core platformunun 2.2.0-dan 2.19.0-a qədər versiyalarında Remote Instances proxy API-də aşkarlanmış autentifikasiya çatışmazlığı zəifliyidir. Bu boşluq autentifikasiya olunmamış uzaqdan hücumçuya təsirlənmiş MWDB instansiyası vasitəsilə digər uzaq MWDB instansiyasına ixtiyari sorğular göndərməyə imkan verir. Təsirlənmiş sistemlərdə dərhal 2.19.0 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of MWDB Core are affected by CVE-2026-66723?
This vulnerability affects MWDB Core versions 2.2.0 through 2.19.0.
What can an unauthenticated attacker do by exploiting CVE-2026-66723?
An unauthenticated remote attacker can send arbitrary requests to a remote MWDB instance through a vulnerable MWDB instance.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.