← volver
CVE-2026-25877

Chartbrew: Insecure Direct Object Reference (IDOR) in Chart Operations

CVSS 6.5 MEDIUMEPSS 0.3%CWE-284
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
06 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs authorization checks based solely on the project_id parameter when handling chart-related operations (update, delete, etc.). No authorization check is performed against the chart_id itself. This allows an authenticated user who has access to any project to manipulate or access charts belonging to other users/ project. This issue has been patched in version 4.8.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Productos afectados
chartbrew · chartbrew

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →