Open-Source Web Application Vulnerability in Chartbrew Exposes Sensitive Data
CVE-2026-40595

7.5HIGH

Key Information:

Vendor

Chartbrew

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-40595?

The vulnerability in Chartbrew, an open-source web application, allows unauthenticated attackers to access and export sensitive chart data from public projects. This flaw arises from inadequate verification of whether a chart should be publicly accessible. Specifically, while project-level public access is checked, individual charts are not, enabling attackers who know the chart identifiers to compromise sensitive data that should remain hidden. The issue was rectified in version 5.0.0 of the application.

Affected Version(s)

chartbrew = 4.9.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.