CVE-2026-32824
datacycle-engine dataCycle-CORE
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply `forwardToUrl` and `redirectUrl` values when triggering password reset or confirmation flows. Those values are then embedded into the outgoing email workflow without host allowlisting. This creates two related abuse paths: - password reset or confirmation links can be sent to a victim with the token already attached...
- CVSS
- 7.3
- EPSS
- 0.30% 21.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.21