Data Enumeration Flaw in dataCycle's Core Processing Module
CVE-2026-32819
4.3MEDIUM
What is CVE-2026-32819?
The vulnerability found in dataCycle-CORE allows standard users to enumerate other users' names and email addresses via a search endpoint, despite restrictions on direct access to user profiles. This issue exposes sensitive information, including internal staff contact details and the existence of guest or external test accounts, thereby breaching user privacy and potentially compromising the integrity of the system.
Affected Version(s)
dataCycle-CORE <= 25.07.3
