Authorization Bypass in Chartbrew Open Source Web Application
CVE-2026-25877

6.5MEDIUM

Key Information:

Vendor

Chartbrew

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-25877?

Chartbrew, an open-source web application used for creating data visualizations from databases and APIs, had a significant authorization bypass flaw in versions prior to 4.8.1. This vulnerability occurs because the application only checks the project_id when performing operations on charts, neglecting to verify the chart_id. As a result, authenticated users with access to any project could manipulate or access charts developed by other users or projects, compromising the integrity of data. This issue has been addressed and patched in version 4.8.1 of the software.

Affected Version(s)

chartbrew < 4.8.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.