Executive brief
Mythic, an open-source command-and-control (C2) framework used by security teams, contains a security flaw that allows users in one operation to view sensitive data from another operation. By using a known identifier from a different project, an authorized user can bypass isolation boundaries to access encryption keys, callback parameters, and infrastructure details. This could lead to the exposure of sensitive engagement data and compromise the operational security of separate teams or clients sharing the same server.
Technical details
An authorization bypass vulnerability exists in Mythic's webserver controllers due to missing operation-scope validation during payload lookups. Specifically, the endpoints c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, and c2profile_sample_message_webhook query the database for a payload by UUID without verifying that the payload's operation_id matches the caller's current operation. An authenticated attacker (operator or spectator) can provide a UUID from a different operation to trigger RabbitMQ RPC calls that return sensitive C2 profile data, including encryption keys (enc_key/dec_key), redirector rules, and IOCs. This vulnerability is addressed in version 3.4.0.60 by adding the necessary operation_id check to the SQL queries.
Affected products
- its-a-feature Mythic < 3.4.0.60
Timeline
- 2026-06-20: disclosed: Issue reported via GitHub issue #564
- 2026-06-21: patched: Version 3.4.0.60 released with fix
- 2026-06-29: advisory: CVE-2026-57952 published
References
- https://github.com/its-a-feature/Mythic/commit/82648e8241b800a32e1882afc310e7316d98ebaa
- https://github.com/its-a-feature/Mythic/issues/564
- https://github.com/its-a-feature/Mythic/releases/tag/v3.4.0.60
- https://www.vulncheck.com/advisories/mythic-unauthorized-c2-profile-configuration-access-via-unverified-payload-uuid