All 3 CVE vulnerabilities found in Mythic, with AI-generated Chinese analysis, references, and POCs.
Vendor: its-a-feature
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57953 | Mythic < 3.4.0.60 - Unauthorized Automation Workflow Modification via eventing_import_automatic_webhook Endpoint CWE-863 | 5.4 | Medium | 2026-06-29 |
| CVE-2026-57952 | Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverified Payload UUID CWE-862 | 5.3 | Medium | 2026-06-29 |
| CVE-2026-57951 | Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table CWE-863 | 6.5 | Medium | 2026-06-29 |
All 3 known CVE vulnerabilities affecting Mythic with full Chinese analysis, references, and POCs where available.