← Volver al buscador de CVEs

CVE-2026-32806

dataCycle-CORE

Descripción

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged user to retrieve server-side rendered admin content that is otherwise hidden by navigation and route checks. On the test instance, a Standard user was able to retrieve the PostgreSQL admin dashboard stats even though /admin itself redirected away. This is patched in 26.06.08.

CVSS 7.5EPSS 0.28700000000000003%Riesgo 0.77
Ver fuente
Publicación
2026-07-20 17:17:05
Versiones afectadas
<=25.07.3
Tipo
Software crítico
Última modificación
2026-07-21 19:35:17
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N