Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-32806— dataCycle Authorization Bypass Via /remote_render

Quick assessment

Affected
datacycle-engine dataCycle-CORE
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

dataCycle dataCycle CORE是奥地利dataCycle组织的一个数据管理系统的核心处理与框架模块。 dataCycle CORE 25.07.3及之前版本存在授权问题漏洞,该漏洞源于对/remote_render端点的访问控制不当,任何已通过身份验证的用户可以通过该端点请求任意的partial或helper-backed render函数,使得低权限用户能够检索到原本被导航和路由检查隐藏的服务器端渲染的管理员内容。

CVSS 7.5 · High EPSS 0.39% · P32

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
datacycle-engine dataCycle-CORE <= 25.07.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-32806

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
dataCycle Authorization Bypass Via /remote_render
Source: CVE Program / CVE List V5
Vulnerability Description
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged user to retrieve server-side rendered admin content that is otherwise hidden by navigation and route checks. On the test instance, a Standard user was able to retrieve the PostgreSQL admin dashboard stats even though /admin itself redirected away. This is patched in 26.06.08.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
dataCycle CORE 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
dataCycle dataCycle CORE是奥地利dataCycle组织的一个数据管理系统的核心处理与框架模块。 dataCycle CORE 25.07.3及之前版本存在授权问题漏洞,该漏洞源于对/remote_render端点的访问控制不当,任何已通过身份验证的用户可以通过该端点请求任意的partial或helper-backed render函数,使得低权限用户能够检索到原本被导航和路由检查隐藏的服务器端渲染的管理员内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
datacycle-engine dataCycle-CORE <= 25.07.3 -

II. Public POCs for CVE-2026-32806

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 9013 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-32806

登录查看更多情报信息。

Vendor Advisories for CVE-2026-32806 (1)

Same Patch Batch · datacycle-engine · 2026-07-20 · 9 CVEs total

CVE-2026-32821 8.1 HIGH API Collection Impersonation Via user_email And Missing Object- Level Authorization
CVE-2026-32807 7.5 HIGH dataCycle Public DataLink Text File Download Ignores Validity And Authorization
CVE-2026-32820 7.5 HIGH dataCycle Public Markdown Path Traversal Via /docs/*path
CVE-2026-32825 7.3 HIGH dataCycle No Brute-Force Protection On Web And API Login Endpoints
CVE-2026-32824 7.3 HIGH dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redire
CVE-2026-32822 6.1 MEDIUM dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages
CVE-2026-32823 4.3 MEDIUM dataCycle State-Changing GET Endpoints Enable CSRF
CVE-2026-32819 4.3 MEDIUM dataCycle User Directory Enumeration Via /users/search

IV. Related Vulnerabilities

V. Comments for CVE-2026-32806

No comments yet


Leave a comment