CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-66723

unknowncovered by 1 sourcefirst seen 2026-07-29
MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for incoming requests, allowing an unauthenticated remote attacker to send arbitrary requests to a remote MWDB instance using the identity and permissions associated with the configured API key. This can result in unauthorized actions being performed on the remote instance as if executed by the user whose API key was used to set up the remote instance. The vulnerability is limited to deployments where Remote Instances have been configured.This issue has been fixed in version 2.19.0

⚡ Watch CVE-2026-66723

Get an email if CVE-2026-66723 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-66723

CVE.org record

Embed the live status

CVE-2026-66723 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-66723 status](https://www.csirts.com/badge/CVE-2026-66723)](https://www.csirts.com/cve/CVE-2026-66723)