Reflected DOM XSS Vulnerability in dataCycle Data Management System
CVE-2026-32822

6.1MEDIUM

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-32822?

The dataCycle data management system features a vulnerability within its core processing module, which affects all versions before 25.07.3. This security flaw allows unauthenticated attackers to exploit the system by injecting arbitrary HTML into flash notifications on public routes. Utilizing the frontend toast component, the malicious content can be dynamically merged into the Document Object Model (DOM) through the use of innerHTML. This reflected DOM XSS can be triggered via crafted links to public pages, such as the /docs section, and is not limited to administrative interfaces, thereby posing a significant risk to all users accessing the application.

Affected Version(s)

dataCycle-CORE <= 25.07.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.