Improper Authorization in Chartbrew Web Application by Chartbrew
CVE-2026-40603

6.5MEDIUM

Key Information:

Vendor

Chartbrew

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-40603?

Inversion of access controls in Chartbrew version 4.9.0 allows authenticated users to access project-specific report data and passwords without appropriate permissions. The application fails to enforce project-level authorization, which could lead to unauthorized disclosure of sensitive information. This vulnerability has been addressed in version 5.0.0, which rectifies the authorization flaw and enhances data protection.

Affected Version(s)

chartbrew = 4.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.