CVE-2026-25877

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs authorization checks based solely on the project_id parameter when handling chart-related operations (update, delete, etc.). No authorization check is performed against the chart_id itself. This allows an authenticated user who has access to any project to manipulate or access charts belonging to other users/ project. This issue has been patched in version 4.8.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:depomo:chartbrew:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-06 05:16

Updated : 2026-03-10 14:09


NVD link : CVE-2026-25877

Mitre link : CVE-2026-25877

CVE.ORG link : CVE-2026-25877


JSON object : View

Products Affected

depomo

  • chartbrew
CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key