By vendor
Its-A-Feature vulnerabilities
Known CVEs affecting Its-A-Feature products, prioritized by severity, with SEC.co remediation and detection guidance.
3 published vulnerabilities
- CVE-2026-57951MEDIUM 6.5
Mythic command and control framework versions before 3.4.0.60 suffer from a database access control flaw that allows authenticated users to read sensitive output from any operation on the server, regardless of their assigned permissions. The vulnerability stems from a misconfigured permission filter in the backend that treats an OR condition as always-true, effectively removing restrictions. Any user with valid credentials—including those with minimal spectator roles—can extract step output, names, and descriptions from the payload_build_step table across all operations.
- CVE-2026-57953MEDIUM 5.4
Mythic, an operations management platform, contains an access control flaw that allows users with spectator-only permissions to perform actions they should not be able to do. Spectators are intended to have read-only visibility, but due to a misconfigured endpoint, they can instead create and delete automation workflows. This means someone with limited access can make unauthorized changes to how operations are automated, potentially disrupting or redirecting workflows. The vulnerability affects versions before 3.4.0.60.
- CVE-2026-57952MEDIUM 5.3
Mythic, a command-and-control framework, contains a flaw that allows operators with access to one attack operation to view sensitive configuration details—including encryption keys—from a completely different operation. This works because four specific API endpoints do not properly verify that a request belongs to the operation it claims to access. An attacker with any valid operator account can exploit this by guessing or knowing a configuration ID from another operation and accessing its secrets. The vendor patched this in version 3.4.0.60.