Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mvr-4jqv-324m

Опубликовано: 29 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.

Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.

EPSS

Процентиль: 37%
0.00438
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.

EPSS

Процентиль: 37%
0.00438
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-863