CVE-2026-32821
Last modified
CVE-2026-32821 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to evaluate permissions as a different user by supplying `user_email`. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to evaluate permissions as a different user by supplying `user_email`. If the target user has collections, this can expose those collections through the API. In V4, once a collection id is known, the same controller also offers `add_item` and `remove_item` routes without any object-level `authorize!` checks, creating a likely cross-user modification path. This is patched in version 26.06.08.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| datacycle-engine | dataCycle-CORE | <= 25.07.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-32821?
How severe is CVE-2026-32821?
How do I fix CVE-2026-32821?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32816Admidio is an open-source user management solution. In versi…5.7
- CVE-2026-32817Admidio is an open-source user management solution. In versi…9.1
- CVE-2026-32818Admidio is an open-source user management solution. In versi…6.5
- CVE-2026-32819dataCycle is a data management system for centrally storing,…4.3
- CVE-2026-3282A flaw has been found in libvips 8.19.0. This vulnerability …7.1
- CVE-2026-32820dataCycle is a data management system for centrally storing,…7.5
- CVE-2026-32822dataCycle is a data management system for centrally storing,…6.1
- CVE-2026-32823dataCycle is a data management system for centrally storing,…4.3
- CVE-2026-32824dataCycle is a data management system for centrally storing,…7.3
- CVE-2026-32825dataCycle is a data management system for centrally storing,…7.3
- CVE-2026-32828Kargo manages and automates the promotion of software artifa…4.9
- CVE-2026-32829lz4_flex is a pure Rust implementation of LZ4 compression/de…7.5
Are you affected by CVE-2026-32821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
