CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-66724

unknowncovered by 1 sourcefirst seen 2026-07-29
MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST method, which bypasses the capability checks applied to the documented PUT method. This allows any authenticated user without the adding_configs or adding_blobs capabilities to upload config and text blob objects to the system. The impact is limited to adding new config and blob objects. This issue has been fixed in version 2.19.0

⚡ Watch CVE-2026-66724

Get an email if CVE-2026-66724 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-66724

CVE.org record

Embed the live status

CVE-2026-66724 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-66724 status](https://www.csirts.com/badge/CVE-2026-66724)](https://www.csirts.com/cve/CVE-2026-66724)