mediumCVSS 7.3Vulnerability

CVE-2026-7711

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
MindsDB has an Improper Access Control Issue
epss_score
0.00284
cvss_score
7.3
ghsa_published
2026-05-04T00:30:25Z
source_url
https://github.com/advisories/GHSA-9f6m-65v9-x9g2
ghsa_updated
2026-05-08T16:23:18Z
ghsa_id
GHSA-9f6m-65v9-x9g2
cve_id
CVE-2026-7711
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.21121

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/MindsDB

AFFECTS (1)

[Software]pip/MindsDB

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7711 (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal