PT-2026-23639 · Chartbrew · Chartbrew

Highrazvanilin

·

Publicado

2026-03-06

·

Atualizado

2026-03-11

·

CVE-2026-27603

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.4
Description Chartbrew is a web application that connects to databases and APIs to create charts. Prior to version 4.8.4, the chart filter endpoint, ''/project/:project id/chart/:chart id/filter'', lacks both verifyToken and checkPermissions middleware. This allows unauthenticated users to access chart data from any team or project. The project id and chart id are vulnerable parameters.
Recommendations Update to version 4.8.4 or later.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27603
GHSA-9FHR-5VVC-P455

Produtos afetados

Chartbrew