PT-2026-36162 · Chartbrew · Chartbrew

Larlarua

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-40601

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 5.0.0
Description Chartbrew is an open-source web application used to create charts by connecting to databases and APIs. The application exposes the "POST /api/chart/:chart id/query" endpoint without authentication. The system only verifies the team.allowReportRefresh setting and fails to check if the target chart belongs to a public report, if the project is public, or if the sharing policy permits the operation. An unauthenticated attacker with a chart identifier can trigger a data refresh and retrieve current data from private charts.
Recommendations Update to version 5.0.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40601

Affected Products

Chartbrew