What is CVE-2026-66724?
MWDB Core versions from 2.0.0 to below 2.19.0 have a missing authorization vulnerability in deprecated config and blob upload endpoints, allowing any authenticated user to bypass capability checks via the undocumented POST method. Updating to version 2.19.0 or later is strongly recommended.
Azərbaycanca: MWDB Core 2.0.0 ilə 2.19.0 arası versiyalarda köhnəlmiş konfiqurasiya və blob yükləmə "endpoint"lərində səlahiyyət yoxlaması çatışmazlığı mövcuddur. Autentifikasiya olunmuş istənilən istifadəçi POST metodu vasitəsilə bu "endpoint"lərə icazəsiz giriş əldə edə bilər. Dərhal 2.19.0 və ya daha yuxarı versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of MWDB Core are affected by CVE-2026-66724?
Versions from 2.0.0 to below 2.19.0 are affected. Version 2.19.0 and later have addressed this issue.
Does exploiting CVE-2026-66724 require authentication?
Yes, any authenticated user can bypass capability checks on the deprecated config and blob upload endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.