PT-2026-53670 · Its A Feature · Mythic

George Chen

·

Published

2026-06-29

·

Updated

2026-06-29

·

CVE-2026-57952

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile config check webhook, c2profile redirect rules webhook, c2profile get ioc webhook, c2profile sample message webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57952

Affected Products

Mythic