Data Management System Vulnerability in dataCycle by DataCycle Inc.
CVE-2026-32806

7.5HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-32806?

In the dataCycle-CORE application, prior to version 25.07.3, an access control vulnerability exists that allows authenticated users to exploit the /remote_render endpoint. This flaw permits any logged-in user to request and render arbitrary partials or helper-backed render functions without proper authorization checks. As a result, low-privileged users could access sensitive server-side rendered content, such as admin dashboard statistics, that should be restricted. This significant misconfiguration could expose critical data and lead to unauthorized information retrieval. A patch addressing this vulnerability has been implemented in version 26.06.08.

Affected Version(s)

dataCycle-CORE <= 25.07.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.