Two high-severity vulnerabilities in Chartbrew 4.9.0 allowed authenticated users with access to one project in a team to interfere with resources belonging to other projects in the same team. In CVE-2026-40904, dataset and dataRequest routes relied on team-scoped permission checks instead of confirming that the referenced dataset_id, dataRequest ID, and connection_id belonged to projects the user was authorized to access. That flaw exposed cross-project datasets and data requests to unauthorized read, execute, create, update, and delete actions, and could also enable misuse of victim-side database or API connections.
A second flaw, tracked as CVE-2026-40600, affected Chartbrew's project share policy routes. The application validated the project in the URL path but did not ensure the supplied policy_id was tied to that project, allowing users to update or delete SharePolicy records from other projects. Attackers could therefore change dashboard sharing settings such as visibility, password protection, allowed parameters, and expiration rules across project boundaries. Both issues were fixed in Chartbrew 5.0.0.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The identified access control vulnerabilities affecting dataset, dataRequest, and project share policy routes were fixed in Chartbrew version 5.0.0.
Chartbrew version 4.9.0 was affected by two authorization issues: one allowed low-privileged users to access and manipulate datasets and data requests across other projects in the same team, and another allowed authenticated users to update or delete SharePolicy records tied to different projects. Together, the flaws enabled cross-project data exposure and unauthorized changes to dashboard sharing settings.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.