CVE-2026-32252Disclosure(depomo / chartbrew)

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch depomo chartbrew systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew in GET /team/:team_id/template/generate/:project_id. The GET handler calls checkAccess(req, "updateAny", "chart") without awaiting the returned promise, and it does not verify that the supplied project_id belongs to req.params.team_id or to the caller's team. As a result, an authenticated attacker with valid template-generation permissions in their own team can request the template model for a project belonging to another team and receive victim project data. This vulnerability is fixed in 4.9.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chartbrew

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
chartbrew

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-10: 2Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 204-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32252 Cross-Tenant Authorization Bypass in Chartbrew Prior to Version 4.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32252

    Post summary

    The entry references CVE‑2026‑32252 and identifies a cross‑tenant authorization bypass in Chartbrew before version 4.9.0, but it provides no exploit details, patches, or evidence of active exploitation.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-32252 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authoriz… https://www.cve.org/CVERecord?id=CVE-2026-32252

    Post summary

    CVE-2026-32252 affects Chartbrew with a cross‑tenant authorization flaw, and it is addressed in version 4.9.0.

    0000070
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdepomochartbrew---

Explore more