Executive brief
Mythic, an open-source command and control (C2) framework used for security operations, contains a flaw where users with restricted 'spectator' access can perform unauthorized actions. While spectators are intended to have read-only access, this vulnerability allows them to create or delete automation workflows within their assigned operation. This could allow a restricted user to disrupt active security operations or modify how the system automatically responds to events.
Technical details
An incorrect authorization (CWE-863) vulnerability exists in Mythic's web server routing. The 'eventing_import_automatic_webhook' endpoint was incorrectly registered under 'RBACMiddlewareAll', which includes the 'spectator' role, instead of 'RBACMiddlewareNoSpectators'. An authenticated attacker with spectator privileges can send POST requests to this endpoint to write files to disk, insert database records, and soft-delete existing EventGroups. This allows for the unauthorized modification of automation workflows and EventGroups within the scope of the attacker's current operation. The issue is resolved in version 3.4.0.60.
Affected products
- its-a-feature Mythic < 3.4.0.60
Timeline
- 2026-06-20: disclosed: Issue reported via GitHub
- 2026-06-21: patched: Version 3.4.0.60 released
- 2026-06-29: advisory: CVE published to NVD
References
- https://github.com/its-a-feature/Mythic/commit/82648e8241b800a32e1882afc310e7316d98ebaa
- https://github.com/its-a-feature/Mythic/issues/565
- https://github.com/its-a-feature/Mythic/releases/tag/v3.4.0.60
- https://www.vulncheck.com/advisories/mythic-unauthorized-automation-workflow-modification-via-eventing-import-automatic-webhook-endpoint