PT-2026-53670 · Its A Feature · Mythic

George Chen

·

Publicado

2026-06-29

·

Atualizado

2026-06-29

·

CVE-2026-57952

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile config check webhook, c2profile redirect rules webhook, c2profile get ioc webhook, c2profile sample message webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-57952

Produtos afetados

Mythic