CVE-2026-7711High· 7.3▾ TwilightMindsDB has an Improper Access Control Issue
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
mindsdb <= 26.0.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
CVE-2026-27483High· 8.8MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
CVE-2026-86173High· 7.5MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list