CVE-2026-57953
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized
CVSS
5.4
Medium
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Published: Jun 29, 2026 · Last modified: Jul 14, 2026 · CWE-863
0.2%EPSS · 30 days0.3%
2026-06-302026-07-20
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under spectator-permitted middleware. Attackers with spectator role can exploit this misconfigured access control to create and delete automation workflows, making unauthorized modifications to operation automation configuration and EventGroups.
- github.comhttps://github.com/its-a-feature/Mythic/commit/82648e8241b800a32e1882afc310e7316d98ebaa
- github.comhttps://github.com/its-a-feature/Mythic/issues/565
- github.comhttps://github.com/its-a-feature/Mythic/releases/tag/v3.4.0.60
- www.vulncheck.comhttps://www.vulncheck.com/advisories/mythic-unauthorized-automation-workflow-modification-via-eventing-import-automatic-webhook-endpoint
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-350298.8 HIG97.8%
——29LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables. Fixed in v1.83.0.6dCVE-2026-479967.6 HIG96.9%
——29Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.5dCVE-2025-324622.8 LOW87.2%
——26Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.6dCVE-2021-289367.5 HIG78.9%
——24The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.12dCVE-2021-406397.5 HIG64.5%
——19Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.12dCVE-2022-366348.8 HIG59.9%
——18An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.12d