Cross-Site Request Forgery in dataCycle's Core Processing Module
CVE-2026-32823
4.3MEDIUM
What is CVE-2026-32823?
In the dataCycle-CORE system, an insecure handling of GET requests allows attackers to exploit state changes due to insufficient CSRF protections. This vulnerability allows an attacker to manipulate the application state for logged-in users by embedding malicious links, images, or iframes in an unsuspecting user's browser session. The vulnerability specifically affects GET routes that modify user watch lists and can even allow user impersonation for administrators. All affected versions prior to 26.06.08 must be updated to mitigate this security risk.
Affected Version(s)
dataCycle-CORE <= 25.07.3
