top of page
perceptive_background_267k.jpg

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew expos…

Published:

29 April 2026 at 22:00:00

Alert date:

30 April 2026 at 21:02:39

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

CVE-2026-40601 affects Chartbrew version 4.9.0, an open-source web application for creating charts from databases and APIs. The vulnerability exposes the POST /api/chart/:chart_id/query endpoint without proper authentication. The endpoint only checks team.allowReportRefresh but fails to verify if the target chart belongs to a public report, if the project is public, or if sharing policies allow the operation. An unauthenticated attacker who knows a chart identifier can trigger data refresh and retrieve current data from private charts. This represents a significant data exposure risk for private chart data. The issue has been patched in version 5.0.0.

Technical details

Mitigation steps:

Affected products:

Chartbrew

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page