PT-2026-53670 · Its A Feature · Mythic
George Chen
·
Published
2026-06-29
·
Updated
2026-06-29
·
CVE-2026-57952
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile config check webhook, c2profile redirect rules webhook, c2profile get ioc webhook, c2profile sample message webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mythic