


Perceptive Security
SOC/SIEM Consultancy

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew expos…
Published:
29 April 2026 at 22:00:00
Alert date:
30 April 2026 at 21:02:39
Source:
nvd.nist.gov
Web Technologies
CVE-2026-40601 affects Chartbrew version 4.9.0, an open-source web application for creating charts from databases and APIs. The vulnerability exposes the POST /api/chart/:chart_id/query endpoint without proper authentication. The endpoint only checks team.allowReportRefresh but fails to verify if the target chart belongs to a public report, if the project is public, or if sharing policies allow the operation. An unauthenticated attacker who knows a chart identifier can trigger data refresh and retrieve current data from private charts. This represents a significant data exposure risk for private chart data. The issue has been patched in version 5.0.0.
Technical details
Mitigation steps:
Affected products:
Chartbrew
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40601
https://github.com/chartbrew/chartbrew/releases/tag/v5.0.0
https://github.com/chartbrew/chartbrew/security/advisories/GHSA-cpr6-mhgm-893w
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
