Executive brief
MWDB Core, a malware repository and analysis platform, contains a security flaw in its Remote Instances feature. An unauthenticated attacker can bypass security checks to send commands to remote connected servers using the identity and full permissions of the administrator who set up the connection. This could allow unauthorized parties to view sensitive malware data or modify configurations on remote systems.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Remote Instances proxy API of MWDB Core. The proxy API fails to verify the authentication of incoming requests before forwarding them to configured remote instances. An unauthenticated remote attacker can exploit this to send arbitrary requests to a remote MWDB instance, which are then executed using the API key and associated permissions of the user who configured the remote connection. This vulnerability only affects deployments where the experimental 'Remote Instances' feature is enabled. The issue is resolved in version 2.19.0 by enforcing proper authorization requirements on Remote API endpoints.
Affected products
- CERT.PL MWDB Core >=2.2.0, <2.19.0
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory
- 2026-07-29: patched