Data Disclosure Vulnerability in Chartbrew Web Application by Chartbrew
CVE-2026-40904

8.1HIGH

Key Information:

Vendor

Chartbrew

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-40904?

Chartbrew, an open-source web application that enables users to create charts from various databases and APIs, has a significant flaw in version 4.9.0. This vulnerability allows low-privileged project members to gain unauthorized access to datasets and data requests across different projects within the same team. An authenticated attacker, who has access to only one project, can exploit this misconfiguration to read, execute, create, update, and delete data belonging to other projects. The flaw arises from insufficient checks on user permissions, making it easy for attackers with basic project-level credentials to compromise project data. This vulnerability has been resolved in version 5.0.0.

Affected Version(s)

chartbrew = 4.9.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.