PT-2026-23638 · Chartbrew · Chartbrew

Q1Uf3Ng

·

Published

2026-03-06

·

Updated

2026-03-25

·

CVE-2026-27005

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.3
Description Chartbrew is a web application that connects to databases and APIs to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against connected databases, including MySQL and PostgreSQL. This allows an attacker to potentially read, modify, or delete data within those databases, depending on the database user's permissions. The issue is related to the applyMysqlOrPostgresVariables function.
Recommendations Update Chartbrew to version 4.8.3 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-27005
GHSA-W5RH-V333-QQ6C

Affected Products

Chartbrew