Data Disclosure Vulnerability in Chartbrew Web Application by Chartbrew
CVE-2026-40904
8.1HIGH
What is CVE-2026-40904?
Chartbrew, an open-source web application that enables users to create charts from various databases and APIs, has a significant flaw in version 4.9.0. This vulnerability allows low-privileged project members to gain unauthorized access to datasets and data requests across different projects within the same team. An authenticated attacker, who has access to only one project, can exploit this misconfiguration to read, execute, create, update, and delete data belonging to other projects. The flaw arises from insufficient checks on user permissions, making it easy for attackers with basic project-level credentials to compromise project data. This vulnerability has been resolved in version 5.0.0.
Affected Version(s)
chartbrew = 4.9.0
