Authorization Bypass in Chartbrew Open Source Web Application
CVE-2026-25877
6.5MEDIUM
What is CVE-2026-25877?
Chartbrew, an open-source web application used for creating data visualizations from databases and APIs, had a significant authorization bypass flaw in versions prior to 4.8.1. This vulnerability occurs because the application only checks the project_id when performing operations on charts, neglecting to verify the chart_id. As a result, authenticated users with access to any project could manipulate or access charts developed by other users or projects, compromising the integrity of data. This issue has been addressed and patched in version 4.8.1 of the software.
Affected Version(s)
chartbrew < 4.8.1
