PT-2026-36161 · Chartbrew · Chartbrew

Larlarua

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-40600

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew version 4.9.0
Description Chartbrew allows authenticated users with access to one project to update or delete a SharePolicy record belonging to a different project. The application authorizes the caller based on the project in the URL path but fails to verify if the policy id belongs to that specific project. This enables cross-project modification of dashboard sharing rules, including visibility, password requirements, allowed parameters, and expiration settings.
Recommendations Update to version 5.0.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40600

Affected Products

Chartbrew