


Perceptive Security
SOC/SIEM Consultancy

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew expos…
Published:
29 april 2026 om 22:00:00
Alert date:
30 april 2026 om 21:02:39
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Chartbrew version 4.9.0 contains an authorization bypass vulnerability that allows authenticated attackers with access to one project within a team to perform unauthorized operations on datasets and data requests belonging to other projects in the same team. The vulnerability stems from improper authorization at the team level instead of project-specific binding. Attackers can read, execute, create, update, and delete datasets across projects, leading to cross-project data disclosure and unauthorized database/API access. The issue affects multiple dataset and dataRequest endpoints and is exploitable remotely with standard project-level credentials. A patch is available in version 5.0.0.
Technical details
Mitigation steps:
Affected products:
Chartbrew
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40904
https://github.com/chartbrew/chartbrew/releases/tag/v5.0.0
https://github.com/chartbrew/chartbrew/security/advisories/GHSA-jq95-gqww-vhm3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
