CVE-2026-40600Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to one project to update or delete a SharePolicy record that belongs to a different project. The affected routes authorize the caller against the project in the URL path, but they never verify that policy_id belongs to that project. This permits cross-project modification of dashboard sharing rules, including visibility, password requirements, allowed parameters, and expiration settings. This issue has been patched in version 5.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Technical Details · 2026-04-30: 104-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40600 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows auth… https://www.cve.org/CVERecord?id=CVE-2026-40600

    Post summary

    The statement references CVE‑2026‑40600 and notes an affected version of Chartbrew but gives no details on the vulnerability, exploitation, or remediation.

    00010131
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40600 Improper Authorization in Chartbrew 4.9.0 Allows Cross-Project SharePolicy Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40600

    Post summary

    A new CVE (CVE‑2026‑40600) has been disclosed, detailing an improper authorization flaw in Chartbrew 4.9.0 that permits cross‑project SharePolicy modifications, with no indications of exploitation or remediation yet.

    0000027
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40600 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows auth… https://www.cve.org/CVERecord?id=CVE-2026-40600 ----- Traducción: CVE-2026-40600 Cha… http://infoflow.cloud`

    Post summary

    The post lists the CVE and a brief mention of the affected application, but provides no substantive details on exploitation, mitigation, or severity.

    0000012
    75 followersView on X

Explore more