


Perceptive Security
SOC/SIEM Consultancy

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allow…
Published:
29 April 2026 at 22:00:00
Alert date:
30 April 2026 at 21:02:39
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Chartbrew version 4.9.0 contains a vulnerability allowing authenticated users to modify or delete SharePolicy records belonging to other projects. The flaw stems from inadequate authorization checks where routes verify project access but fail to validate that policy_id belongs to the authorized project. This enables unauthorized cross-project modification of dashboard sharing configurations including visibility settings, password requirements, allowed parameters, and expiration controls. The vulnerability affects multi-tenant deployments where project isolation is critical for security. A patch has been released in version 5.0.0 that addresses the authorization bypass issue.
Technical details
Mitigation steps:
Affected products:
Chartbrew
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40600
https://github.com/chartbrew/chartbrew/releases/tag/v5.0.0
https://github.com/chartbrew/chartbrew/security/advisories/GHSA-pq8h-2h99-39xm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
