CVE-2026-27603Disclosure(depomo / chartbrew)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch depomo chartbrew systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST /project/:project_id/chart/:chart_id/filter is missing both verifyToken and checkPermissions middleware, allowing unauthenticated users to access chart data from any team/project. This issue has been patched in version 4.8.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chartbrew

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
chartbrew

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-10: 103-0603-1003-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-061
Patch1
2026-03-101
Disclosure1
2026-03-111
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27603 (CVSS:8.7, HIGH) is Analyzed. Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c..https://nvd.nist.gov/vuln/detail/CVE-2026-27603 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The message announces CVE‑2026‑27603, notes its high CVSS score, and links to the NVD entry, but provides no PoC, exploit code, patch, or detailed technical info.

    0000024
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Chartbrew, Authentication Bypass, #CVE-2026-27603 (HIGH) https://dailycve.com/chartbrew-authentication-bypass-cve-2026-27603-high/

    Post summary

    This post announces the newly disclosed CVE-2026-27603 in Chartbrew, identifying it as a high‑severity authentication bypass vulnerability, and provides a link for additional details.

    0000021
    167 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-27603 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filte… https://www.cve.org/CVERecord?id=CVE-2026-27603

    Post summary

    The CVE concerns Chartbrew; the issue is presumably fixed in version 4.8.4, with no PoC, exploit, or active exploitation reported.

    00000112
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdepomochartbrew---

Explore more