PT-2026-36161 · Chartbrew · Chartbrew
Larlarua
·
Published
2026-04-30
·
Updated
2026-04-30
·
CVE-2026-40600
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Chartbrew version 4.9.0
Description
Chartbrew allows authenticated users with access to one project to update or delete a SharePolicy record belonging to a different project. The application authorizes the caller based on the project in the URL path but fails to verify if the
policy id belongs to that specific project. This enables cross-project modification of dashboard sharing rules, including visibility, password requirements, allowed parameters, and expiration settings.Recommendations
Update to version 5.0.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chartbrew