CVE-2026-32806
datacycle-engine dataCycle-CORE
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions through /remote_render. The endpoint does not restrict which partial can be rendered and does not apply controller-specific authorization before rendering the selected view. This enables a low-privileged user to retrieve server-side rendered admin content that is otherwise hidden...
- CVSS
- 7.5
- EPSS
- 0.29% 20.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.21