Data Management System Vulnerability in dataCycle by DataCycle Inc.
CVE-2026-32806
7.5HIGH
What is CVE-2026-32806?
In the dataCycle-CORE application, prior to version 25.07.3, an access control vulnerability exists that allows authenticated users to exploit the /remote_render endpoint. This flaw permits any logged-in user to request and render arbitrary partials or helper-backed render functions without proper authorization checks. As a result, low-privileged users could access sensitive server-side rendered content, such as admin dashboard statistics, that should be restricted. This significant misconfiguration could expose critical data and lead to unauthorized information retrieval. A patch addressing this vulnerability has been implemented in version 26.06.08.
Affected Version(s)
dataCycle-CORE <= 25.07.3
