PT-2026-61627 · Unknown · Datacycle-Core

CVE-2026-32820

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions dataCycle-CORE versions prior to 26.06.08
Description The documentation and static markdown renderer in the core processing and framework rules module accepts attacker-controlled path segments. Because these segments are only processed by the Rails HTML sanitizer, which fails to remove directory traversal sequences, an unauthenticated attacker can access and render arbitrary .md files from the application root or engine root by traversing outside the intended docs or static directories.
Recommendations Update dataCycle-CORE to version 26.06.08.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32820

Affected Products

Datacycle-Core