CVE-2026-57952
EUVD-2026-4016929.06.2026, 18:16
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in one operation can invoke these endpoints with a known payload UUID from another operation to access that operation's C2 profile configuration including encryption keys and callback parameters.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| its-a-feature | mythic | 𝑥 < 3.4.0.60 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References