top of page
perceptive_background_267k.jpg

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allow…

Published:

29 april 2026 om 22:00:00

Alert date:

30 april 2026 om 21:02:39

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

Chartbrew version 4.9.0 contains a vulnerability allowing authenticated users to modify or delete SharePolicy records belonging to other projects. The flaw stems from inadequate authorization checks where routes verify project access but fail to validate that policy_id belongs to the authorized project. This enables unauthorized cross-project modification of dashboard sharing configurations including visibility settings, password requirements, allowed parameters, and expiration controls. The vulnerability affects multi-tenant deployments where project isolation is critical for security. A patch has been released in version 5.0.0 that addresses the authorization bypass issue.

Technical details

Mitigation steps:

Affected products:

Chartbrew

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page