CVE-2026-40595Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level public access and, for exports, a team-level export toggle. The routes do not verify whether the target chart is actually allowed on the public report or whether the governing SharePolicy permits public access. An unauthenticated attacker who knows a chart identifier in a public project can read or export chart data for charts that were intentionally hidden from the report. This issue has been patched in version 5.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Technical Details · 2026-04-30: 104-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-40595 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes pub… https://www.cve.org/CVERecord?id=CVE-2026-40595

    Post summary

    The provided text identifies CVE-2026-40595 but lacks substantial detail about the vulnerability, exploitation, or mitigations.

    00010124
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40595 Unauthorized Chart Data Access in Chartbrew 4.9.0 via SharePolicy... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40595 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑40595, detailing unauthorized chart data access in Chartbrew 4.9.0, but offers no PoC, exploit code, or patch information—only a link to a vulnerability database.

    0000028
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40595 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes pub… https://www.cve.org/CVERecord?id=CVE-2026-40595 ----- Traducción: CVE-2026-40595 Cha… http://infoflow.cloud`

    Post summary

    The post lists CVE‑2026‑40595 for Chartbrew with a brief description and a link to the official CVE record, but provides no details on exploitation, mitigation, or technical specifics.

    0000015
    75 followersView on X

Explore more