PT-2026-36162 · Chartbrew · Chartbrew

·

CVE-2026-40601

·

Published

2026-04-30

·

Updated

2026-04-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 5.0.0
Description Chartbrew is an open-source web application used to create charts by connecting to databases and APIs. The application exposes the "POST /api/chart/:chart id/query" endpoint without authentication. The system only verifies the team.allowReportRefresh setting and fails to check if the target chart belongs to a public report, if the project is public, or if the sharing policy permits the operation. An unauthenticated attacker with a chart identifier can trigger a data refresh and retrieve current data from private charts.
Recommendations Update to version 5.0.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40601
GHSA-CPR6-MHGM-893W

Affected Products

Chartbrew