Executive brief
MWDB Core is a repository used by security teams to store and analyze malware samples and related configurations. A security flaw in its upload system allows any logged-in user to upload new configuration files and text data, even if they do not have the specific permissions to do so. While this does not allow an attacker to delete or modify existing data, it could be used to clutter the system with unauthorized information.
Technical details
A missing authorization vulnerability exists in the deprecated /api/config/{identifier} and /api/blob/{identifier} endpoints of MWDB Core. While the documented PUT method for these endpoints correctly enforces 'adding_configs' and 'adding_blobs' capability checks, the endpoints also support an undocumented POST method that lacks these authorization guards. An authenticated attacker with low privileges can exploit this by sending a POST request to these endpoints to upload unauthorized config or text blob objects. The impact is limited to the creation of new objects; existing data cannot be modified or deleted. The issue is resolved in version 2.19.0 by removing the unintended POST method support.
Affected products
- CERT.PL MWDB Core >=2.0.0, <2.19.0
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 2.19.0
- 2026-07-29: advisory