PT-2026-61628 · Unknown · Datacycle-Core
CVE-2026-32821
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
dataCycle-CORE versions prior to 26.06.08
Description
An authenticated API user with a valid access token can manipulate the collection API to evaluate permissions as another user by providing the
user email variable. This allows the exposure of collections belonging to the target user. Additionally, in V4, the controller provides add item and remove item routes that lack object-level authorize! checks, enabling unauthorized modification of items across different users once a collection ID is known.Recommendations
Update to version 26.06.08.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datacycle-Core