Data Enumeration Flaw in dataCycle's Core Processing Module
CVE-2026-32819

4.3MEDIUM

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-32819?

The vulnerability found in dataCycle-CORE allows standard users to enumerate other users' names and email addresses via a search endpoint, despite restrictions on direct access to user profiles. This issue exposes sensitive information, including internal staff contact details and the existence of guest or external test accounts, thereby breaching user privacy and potentially compromising the integrity of the system.

Affected Version(s)

dataCycle-CORE <= 25.07.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.