๐Ÿ” CVE Alert

CVE-2026-32806

HIGH 7.5

dataCycle Authorization Bypass Via /remote_render

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged user to retrieve server-side rendered admin content that is otherwise hidden by navigation and route checks. On the test instance, a Standard user was able to retrieve the PostgreSQL admin dashboard stats even though /admin itself redirected away. This is patched in 26.06.08.

CWE CWE-285
Vendor datacycle-engine
Product datacycle-core
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for datacycle-engine datacycle-core

Be the first to know when new high vulnerabilities affecting datacycle-engine datacycle-core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

datacycle-engine / dataCycle-CORE
<= 25.07.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/datacycle-engine/dataCycle-CORE/security/advisories/GHSA-xc6g-2v4c-456c