PT-2026-61626 · Unknown · Datacycle-Core
CVE-2026-32819
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dataCycle-CORE versions prior to 25.07.4
Description
A flaw in the core processing and framework rules module allows a Standard user to enumerate the names and email addresses of other users. This occurs via the
/users/search endpoint, enabling the disclosure of internal staff addresses, full names, and the existence of guest or external test accounts, despite direct access to those user profiles being restricted.Recommendations
Update dataCycle-CORE to version 25.07.4 or later.
Restrict access to the
/users/search endpoint for Standard users as a temporary mitigation.Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datacycle-Core